LifeType 1.0.x and 1.1.x have insufficient access control for all...
Vulnerability Description
LifeType 1.0.x and 1.1.x have insufficient access control for all of the PHP scripts under (1) class/ and (2) plugins/, which allows remote attackers to obtain the installation path via a direct request to any of the scripts, as demonstrated by (a) bayesianfilter.class.php and (b) bootstrap.php, which leaks the path in an error message.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-6112
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.osvdb.org/30685
- http://www.lifetype.net/blog.php/lifetype-development-journal/2006/11/30/full_path_disclosure_vulnerability_in_lifetype_1.0.x_and_1.1.x
- http://securityreason.com/securityalert/1980
- http://www.securityfocus.com/archive/1/453135/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30635
- http://www.netvigilance.com/advisory0008
More from lifetype
View All →Affected Vendor
lifetype
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.