V3 Chat allows remote attackers to obtain the installation path via (1) an invalid id parameter to mail/index.php or (2) membername parameter to messenger/online.php, which displays the path in an error page due to an incorrect SQL statement.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/27395 | vdb entry |
http://www.securityfocus.com/bid/18543 | vdb entry |
http://securitytracker.com/id?1016340 | vdb entry exploit |
http://www.securityfocus.com/archive/1/437755/100/200/threaded | mailing list |
http://www.vupen.com/english/advisories/2006/2474 | vdb entry vendor advisory |
http://www.securityfocus.com/archive/1/438069/100/200/threaded | mailing list |