admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to obtain sensitive information via an invalid id parameter, which reveals the installation path in an error message.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://secunia.com/advisories/35478 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/51164 | vdb entry |
http://www.securityfocus.com/archive/1/504302/100/0/threaded | mailing list |