Vulnerability Details CVE-2005-2897
WEB//NEWS 1.4 allows remote attackers to obtain sensitive information via a direct request to files in the actions directory, which reveal the path in an error message, as demonstrated using cat.add.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.3%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2005-2897
-
cpe:2.3:a:stylemotion:web_news:1.4