CVE-2006-3339 Information

Description

secure/ConfigureReleaseNote.jspa in Atlassian JIRA 3.6.2-156 allows remote attackers to obtain sensitive information via unspecified manipulations of the projectId parameter which displays the installation path and other system information in an error message.

Reference

http://jira.atlassian.com/browse/JRA-10542 http://pridels0.blogspot.com/2006/06/atlassian-jira-information-disclosure.html http://www.osvdb.org/26745 http://www.vupen.com/english/advisories/2006/2472 https://exchange.xforce.ibmcloud.com/vulnerabilities/27235

Share on: