ImageFolio 2.23 through 2.27 allows remote attackers to obtain sensitive information via a nonexistent image category, which leaks the web root in the resulting error message.
Link | Tags |
---|---|
http://online.securityfocus.com/archive/1/276133 | mailing list |
http://www.securityfocus.com/bid/4976 | vdb entry exploit |
http://www.iss.net/security_center/static/9308.php | vdb entry |