CVE-2005-0310
Last modified
CVE-2005-0310 is a vulnerability of currently unknown severity. Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.info.php, (3) security.info.php, (4) formcontrol.php, or (5) file_modules.php, which reveals the path in an error message because the pathos_core_version variable is undefined.. EPSS estimates a 1.72% chance of exploitation in the next 30 days.
Description
Exponent 0.95 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) search.info.php, (2) permissions.info.php, (3) security.info.php, (4) formcontrol.php, or (5) file_modules.php, which reveals the path in an error message because the pathos_core_version variable is undefined.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Exponent | Exponent | 0.95 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0310?
How severe is CVE-2005-0310?
How do I fix CVE-2005-0310?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-0304Directory traversal vulnerability in DivX Player 2.6 and ear…
- CVE-2005-0305CRLF injection vulnerability in users.php in Siteman 1.1.10 …
- CVE-2005-0306MercuryBoard 1.1.1 allows remote attackers to gain sensitive…
- CVE-2005-0307Multiple cross-site scripting (XSS) vulnerabilities in index…
- CVE-2005-0308Buffer overflow in the wsprintf function in W32Dasm 8.93 and…
- CVE-2005-0309Multiple cross-site scripting (XSS) vulnerabilities in (1) i…
- CVE-2005-0311Ingate Firewall 4.1.3 and earlier does not terminate the PPT…
- CVE-2005-0312WarFTPD 1.82 RC9, when running as an NT service, allows remo…
- CVE-2005-0313Multiple directory traversal vulnerabilities in Magic Winmai…
- CVE-2005-0314Cross-site scripting (XSS) vulnerability in user.php in Magi…
- CVE-2005-0315The FTP service in Magic Winmail Server 4.0 Build 1112 does …
- CVE-2005-0316WebWasher Classic 2.2.1 and 3.3, when running in server mode…
Are you affected by CVE-2005-0310?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
