Annuaire (Directory) 1.0 allows remote attackers to obtain sensitive information via a direct request to include/lang-en.php, which reveals the full installation path.
Link | Tags |
---|---|
http://www.osvdb.org/24302 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/25668 | vdb entry |
http://osvdb.org/ref/24/24302-annuaire_directory.txt | |
http://secunia.com/advisories/19548 | third party advisory |