phpBB 2.0.18 allows remote attackers to obtain sensitive information via a large SQL query, which generates an error message that reveals SQL syntax or the full installation path.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=113200740718682&w=2 | mailing list |
http://marc.info/?l=bugtraq&m=113210133012767&w=2 | mailing list |
http://securityreason.com/achievement_exploitalert/4 | exploit |