Advanced Guestbook 2.4.2 allows remote attackers to obtain sensitive information...
Vulnerability Description
Advanced Guestbook 2.4.2 allows remote attackers to obtain sensitive information via an invalid (1) GB_TBL parameter to (a) lang/codes-english.php or (b) image.php, which reveal the database name; (2) an invalid GB_DB parameter to index.php, coupled with a ../index lang cookie, which reveals the installation path; or (3) a direct request to index.php with no parameters or cookies, which reveals the installation path.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-0608
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.osvdb.org/33879
- http://www.securityfocus.com/archive/1/467940/100/0/threaded
- http://www.netvigilance.com/advisory0011
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34161
- http://securityreason.com/securityalert/2661
- http://www.vupen.com/english/advisories/2007/1726
- http://www.osvdb.org/33878
- http://osvdb.org/34362
- http://www.osvdb.org/33876
- http://secunia.com/advisories/25153
More from advanced guestbook
View All →Affected Vendor
advanced guestbook
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.