Iono allows remote attackers to obtain the full server path via certain requests to (1) templates/iono/admin/denied.tpl.php, (2) templates/iono/admin/index.tpl.php, and (a) other unspecified files in templates/.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/29505 | vdb entry |
http://securityreason.com/securityalert/2386 | third party advisory |
http://www.osvdb.org/32410 | vdb entry |
http://www.osvdb.org/32412 | vdb entry |
http://www.osvdb.org/32411 | vdb entry |
http://www.securityfocus.com/archive/1/448446/100/0/threaded | mailing list |