Unrated severityNVD Advisory· Published Oct 30, 2007· Updated Apr 23, 2026
CVE-2007-4861
CVE-2007-4861
Description
SAXON 5.4, with display_errors enabled, allows remote attackers to obtain sensitive information via (1) a direct request for news.php, (2) an invalid use of a newsid array parameter to admin/edit-item.php, and possibly unspecified vectors related to additional scripts in (3) admin/, (4) rss/, and (5) the root directory of the installation, which reveal the path in various error messages.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- osvdb.org/45330nvd
- osvdb.org/45331nvd
- osvdb.org/45332nvd
- osvdb.org/45333nvd
- osvdb.org/45334nvd
- securityreason.com/securityalert/3311nvd
- www.netvigilance.com/advisory0053nvd
- www.quirm.net/punbb/viewtopic.phpnvd
- www.securityfocus.com/archive/1/482930/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/38138nvd
News mentions
0No linked articles in our index yet.