PsychoStats 3.0.6b and earlier allows remote attackers to obtain sensitive information via a request for server.php with a missing or invalid newtheme parameter, which reveals a path in an error message.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/24039 | vdb entry |
http://osvdb.org/39738 | vdb entry |
http://marc.info/?l=full-disclosure&m=117947165628273&w=2 | mailing list |
http://osvdb.org/36582 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34366 | vdb entry |
http://marc.info/?l=full-disclosure&m=117948032428148&w=2 | mailing list |