search.php in Geeklog 1.4.x before 1.4.0rc1, and 1.3.x before 1.3.11sr3, allows remote attackers to obtain sensitive information via invalid (1) datestart and (2) dateend parameters, which leaks the web server path in an error message.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2005-12-05T11:00:00
Updated: 2024-08-07T23:31:48.967Z
Reserved: 2005-12-05T00:00:00
Link: CVE-2005-4026

No data.

Status : Modified
Published: 2005-12-05T11:03:00.000
Modified: 2024-11-21T00:03:19.283
Link: CVE-2005-4026

No data.