vendor:
Habari
by:
High-Tech Bridge SA - Ethical Hacking & Penetration Testing
3,3
CVSS
LOW
Path disclosure & XSS
200
CWE
Product Name: Habari
Affected Version From: 0.6.5
Affected Version To: 0.6.5
Patch Exists: YES
Related CWE: N/A
CPE: a:habari:habari:0.6.5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Browser
2010
Path disclosure & XSS in Habari
The vulnerability exists due to failure in the "/system/admin/header.php" & "/system/admin/comments_items.php" script, it's possible to generate an error that will reveal the full path of the script. A remote user can determine the full path to the web root directory and other potentially sensitive information. User can execute arbitrary JavaScript code within the vulnerable application due to failure in the "/system/admin/dash_status.php" & "/system/admin/dash_additem.php" script to properly sanitize user-supplied input in "status_data" & "additem_form" variable when register_globals is on.
Mitigation:
Upgrade to the most recent version