Home    |    View Topics    |    Search    |    Contact Us    |   



Category:   Application (Generic)  >   online-bookmarks Vendors:
online-bookmarks Lets Remote Users Access Restricted Scripts
SecurityTracker Alert ID:  1011561
SecurityTracker URL:
CVE Reference:   GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  Oct 7 2004
Impact:   Not specified
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): prior to 0.4.6
Description:   A vulnerability was reported in online-bookmarks. A remote user can access certain scripts directly.

The vendor reported that the scripts in 'config' directory as well as the bookmarks.php, footer.php, main.php, tree.php, and functions.php scripts can be loaded directly by a remote user.

The vendor did not indicate the impact of accessing the scripts directly except to state that there is a security impact.

Impact:   A remote user can access certain scripts directly, which may result in an unspecified security impact.
Solution:   The vendor has provided a fixed version (0.4.6), available at:

Vendor URL: (Links to External Site)
Cause:   Access control error
Underlying OS:  Linux (Any), UNIX (Any)

Message History:   None.

 Source Message Contents

[Original Message Not Available for Viewing]

Go to the Top of This SecurityTracker Archive Page

Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2021, LLC