phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in advancedsearch.php, and (4) choicelist.php, which reveals the installation path in an error message.
References
Configurations
History
No history.
Information
Published : 2009-10-22 17:30
Updated : 2024-02-04 17:33
NVD link : CVE-2009-3756
Mitre link : CVE-2009-3756
CVE.ORG link : CVE-2009-3756
JSON object : View
Products Affected
kreotek
- phpbms
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor