login.php in 3CX Phone System 6.0.806.0, when 100% disk capacity is reached, allows remote attackers to gain sensitive information via unspecified vectors that reveal the installation path.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://marc.info/?l=full-disclosure&m=122868146707468&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/52452 | vdb entry |