CVE Database
/

CVE-2005-2433

Back to search

CVE-2005-2433

Published: Aug 3, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) usercheck.php in public_html/lists/admin directory, (5) attributes.php, (6) dbcheck.php, (7) importcsv.php, (8) user.php, (9) usermgt.php, or (10) users.php in admin/commonlib/pages directory, (11) helloworld.php, or (12) sidebar.php in public_html/lists/admin/plugins directory, or (13) main.php in public_html/lists/admin/plugsins/defaultplugin directory, which reveal the path in an error message.

VendorProductVersions

n/a

n/a

affected
n/a

References

18329
vdb-entry
x_refsource_OSVDB
18323
vdb-entry
x_refsource_OSVDB
18321
vdb-entry
x_refsource_OSVDB
18326
vdb-entry
x_refsource_OSVDB
18322
vdb-entry
x_refsource_OSVDB
18325
vdb-entry
x_refsource_OSVDB
18327
vdb-entry
x_refsource_OSVDB
18328
vdb-entry
x_refsource_OSVDB
18318
vdb-entry
x_refsource_OSVDB
18324
vdb-entry
x_refsource_OSVDB
18317
vdb-entry
x_refsource_OSVDB
18320
vdb-entry
x_refsource_OSVDB
18319
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now