CVE: CVE-2004-1504

Export to Word

The displaycontent function in config.php for Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to gain sensitive information via a blank show parameter, which reveals the installation path in an error message, as demonstrated using index.php.

Threat-Mapped Scoring

Score: 3.0

Priority: P2 - Serious (High)

EPSS

Score: 0.00462
Percentile: 0.63229

CVSS Scoring

CVSS v2 Score: 5.0

Severity:

Affected Products

← Back to Home