Vulnerability Description
NetClassifieds Premium Edition allows remote attackers to obtain sensitive information via certain requests that reveal the path in an error message, related to the display_errors setting in (1) Common.php and (2) imageresizer.php, and (3) the use of __FILE__ in error reporting by imageresizer.php; and (4) via certain requests that reveal the table name and complete query, related to the Halt_On_Error setting in Mysql_db.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Scriptdevelopers.Net | Netclassifieds | 1.0.1 |
References
- http://osvdb.org/38564
- http://osvdb.org/38565
- http://osvdb.org/38566
- http://osvdb.org/38567
- http://securityreason.com/securityalert/2824
- http://www.securityfocus.com/archive/1/471944/100/0/threaded
- http://www.securityfocus.com/bid/24584
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34997
- http://osvdb.org/38564
- http://osvdb.org/38565
- http://osvdb.org/38566
- http://osvdb.org/38567
- http://securityreason.com/securityalert/2824
- http://www.securityfocus.com/archive/1/471944/100/0/threaded
- http://www.securityfocus.com/bid/24584
FAQ
What is CVE-2007-3356?
CVE-2007-3356 is a vulnerability with a CVSS score of 7.8 (HIGH). NetClassifieds Premium Edition allows remote attackers to obtain sensitive information via certain requests that reveal the path in an error message, related to the display_errors setting in (1) Commo...
How severe is CVE-2007-3356?
CVE-2007-3356 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-3356?
Check the references section above for vendor advisories and patch information. Affected products include: Scriptdevelopers.Net Netclassifieds.