header-logo
Suggest Exploit
vendor:
Siteframe
by:
SecurityFocus
7.5
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: Siteframe
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002

Siteframe Information Disclosure Vulnerability

When handling certain download requests Siteframe may be lead into an error condition. When these errors occur, the script will output some path information. Information obtained in this manner may be used by an attacker to launch further attacks against a vulnerable system.

Mitigation:

Ensure that all requests are properly validated and sanitized before being processed.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/7143/info

Siteframe has been reported vulnerable to an information disclosure vulnerability.

When handling certain download requests Siteframe may be lead into an error condition. When these errors occur, the script will output some path information. 

Information obtained in this manner may be used by an attacker to launch further attacks against a vulnerable system.

http://www.example.com/download.php?id=2%