phpBB 2.0.13 and earlier allows remote attackers to obtain sensitive information via a direct request to oracle.php, which reveals the path in a PHP error message.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=110996579900134&w=2 | mailing list |
http://securitytracker.com/id?1013377 | vdb entry exploit |
http://neosecurityteam.net/Advisories/Advisory-09.txt | exploit |
http://neosecurityteam.tk/index.php?pagina=advisories&id=9 |