CVE-2007-4861
Last modified
CVE-2007-4861 is a vulnerability of currently unknown severity. SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request for news.php, (2) an invalid use of a newsid array parameter to admin/edit-item.php, and possibly unspecified vectors related to additional scripts in (3) admin/, (4) rss/, and (5) the root directory of the installation, which reveal the path in various error messages.. EPSS estimates a 1.81% chance of exploitation in the next 30 days.
Description
SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request for news.php, (2) an invalid use of a newsid array parameter to admin/edit-item.php, and possibly unspecified vectors related to additional scripts in (3) admin/, (4) rss/, and (5) the root directory of the installation, which reveal the path in various error messages.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Quirm | Saxon | 5.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4861?
How severe is CVE-2007-4861?
How do I fix CVE-2007-4861?
Are you affected by CVE-2007-4861?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
