blocker_query.php in Protector System 1.15b1 for PHP-Nuke allows remote attackers to gain sensitive information via a string in the portNum parameter, which reveals the full path in an error message.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/10206 | patch vendor advisory vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15963 | vdb entry |
http://marc.info/?l=bugtraq&m=108276299810121&w=2 | mailing list |
http://www.waraxe.us/index.php?modname=sa&id=25 | vendor advisory |
http://protector.warcenter.se/article-53--0-0.html |