Title: bitweaver users/index.php sort_mode Information Disclosure
Info
Disclosure
Jun 16, 2006
Discovery
Unknown
Dates
Exploit
Jun 16, 2006
Solution
Unknown
Description
Bitweaver contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when invalid input is passed to the 'sort_mode' parameter in /users/index.php, which will disclose full installation path and SQL table informations resulting in a loss of confidentiality.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality
Exploit:
Exploit Public
OSVDB:
Web Related
Solution
Upgrade to version 1.3.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.