HIGH · 7.8

CVE-2007-3356

NetClassifieds Premium Edition allows remote attackers to obtain sensitive information via certain requests that reveal the path in an error message, related to the display_errors setting in (1) Commo...

Vulnerability Description

NetClassifieds Premium Edition allows remote attackers to obtain sensitive information via certain requests that reveal the path in an error message, related to the display_errors setting in (1) Common.php and (2) imageresizer.php, and (3) the use of __FILE__ in error reporting by imageresizer.php; and (4) via certain requests that reveal the table name and complete query, related to the Halt_On_Error setting in Mysql_db.php.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:C/I:N/A:N
Confidentiality
COMPLETE
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Scriptdevelopers.NetNetclassifieds1.0.1

References

FAQ

What is CVE-2007-3356?

CVE-2007-3356 is a vulnerability with a CVSS score of 7.8 (HIGH). NetClassifieds Premium Edition allows remote attackers to obtain sensitive information via certain requests that reveal the path in an error message, related to the display_errors setting in (1) Commo...

How severe is CVE-2007-3356?

CVE-2007-3356 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-3356?

Check the references section above for vendor advisories and patch information. Affected products include: Scriptdevelopers.Net Netclassifieds.