CVE-2007-5128 Information

Share on:

Description

SimpNews 2.41.03 on Windows when PHP before 5.0.0 is used allows remote attackers to obtain sensitive information via an certain link_date parameter to events.php which reveals the path in an error message due to an unsupported argument type for the mktime function on Windows.

Reference

http://forum.boesch-it.de/viewtopic.php?t=2791 http://securityreason.com/securityalert/3174 http://www.netvigilance.com/advisory0068 http://www.securityfocus.com/archive/1/480588/100/0/threaded