Noah's Classifieds 1.3 and earlier allows remote attackers to obtain sensitive information via an invalid list parameter in the showdetails method to index.php, which reveals the path in an error message.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/428157 | mailing list |
http://securityreason.com/securityalert/471 | third party advisory |
http://securityreason.com/securityalert/605 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/25331 | vdb entry |