auction_my_auctions.php in phpbb-Auction 1.2m and earlier allows remote attackers to obtain sensitive information via an invalid mode parameter, which leaks the full path in a PHP error message.
Link | Tags |
---|---|
http://secunia.com/advisories/15029 | third party advisory |
http://securitytracker.com/id?1013779 | vdb entry exploit |
http://www.osvdb.org/15706 | vdb entry |
http://www.snkenjoi.com/secadv/secadv9.txt | exploit |
http://www.phpbb-auction.com/sutra5600.html | patch exploit |