Chipmunk Scripts Guestbook allows remote attackers to obtain the installation path of the script via a URL that causes an error message to be displayed, such as a URL that contains a single quote (') in the start parameter of index.php.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=112982490104274&w=2 | mailing list |
http://www.osvdb.org/20170 | vdb entry |
http://securityreason.com/securityalert/96 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/22825 | vdb entry |
http://irannetjob.com/content/view/148/28/ | url repurposed |