← Back

CVE-2005-2053

nvd nist
Published: Jun 28, 2005Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Just another flat file (JAF) CMS before 3.0 Final allows remote attackers to obtain sensitive information via (1) an * (asterisk) in the id parameter, (2) a blank id parameter, or (3) an * (asterisk) in the disp parameter to index.php, which reveals the path in an error message. NOTE: a followup suggests that this may be a directory traversal or file inclusion vulnerability.

Affected (10)

Jaf Cms
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Salims Softhouse
Version 1.0 final
Version 1.5
Version 2.0.5
Version 2.0 beta
Version 2.0 final
Version 2.1.0
Version 2.5
Version 3.0 rc2
Version 3.0 rc
Version 3.0 rc_fixed

References (6)

Source: cve@mitre.org
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.