marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to obtain sensitive information via an invalid (1) file or (2) category parameter, which reveal the path in an error message.
Link | Tags |
---|---|
http://nukebookmarks.sourceforge.net/ | |
http://zone-h.org/advisories/read/id=7356 | vendor advisory |
http://marc.info/?l=bugtraq&m=111186145609320&w=2 | mailing list |