CVE-2006-2886 Information
Feb 14, 2021
cve
Description
view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote attackers to obtain the full installation path via a crafted fDocumentId parameter which displays the path in the resulting error message. NOTE: this might be resultant from another vulnerability since this vector also produces XSS.
Reference
http://pridels0.blogspot.com/2006/06/knowledgetree-open-source-xss-vuln.html http://www.osvdb.org/26297 https://exchange.xforce.ibmcloud.com/vulnerabilities/26943
Share on: