CVE Database
/

CVE-2006-3938

Back to search

CVE-2006-3938

Published: Jul 31, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php in ecrire/tools/blogroll/; (4) syslog/index.php, (5) thememng/index.php, (6) toolsmng/index.php, (7) utf8convert/index.php in /ecrire/tools/; (8) /ecrire/inc/connexion.php and (9) /inc/session.php; (10) class.blog.php, (11) class.blogcomment.php, (12) and class.blogpost.php in /inc/classes/; (13) append.php, (14) class.xblog.php, (15) class.xblogcomment.php, and (16) class.xblogpost.php in /layout/; (17) form.php, (18) list.php, (19) post.php, or (20) template.php in /themes/default/, which reveal the installation path in error messages.

VendorProductVersions

n/a

n/a

affected
n/a

References

29814
vdb-entry
x_refsource_OSVDB
29828
vdb-entry
x_refsource_OSVDB
29825
vdb-entry
x_refsource_OSVDB
29816
vdb-entry
x_refsource_OSVDB
29826
vdb-entry
x_refsource_OSVDB
29817
vdb-entry
x_refsource_OSVDB
29815
vdb-entry
x_refsource_OSVDB
29818
vdb-entry
x_refsource_OSVDB
29812
vdb-entry
x_refsource_OSVDB
1307
third-party-advisory
x_refsource_SREASON
29830
vdb-entry
x_refsource_OSVDB
29821
vdb-entry
x_refsource_OSVDB
29827
vdb-entry
x_refsource_OSVDB
29831
vdb-entry
x_refsource_OSVDB
29820
vdb-entry
x_refsource_OSVDB
29829
vdb-entry
x_refsource_OSVDB
29823
vdb-entry
x_refsource_OSVDB
29813
vdb-entry
x_refsource_OSVDB
29824
vdb-entry
x_refsource_OSVDB
29822
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now