CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an invalid date value in the from_date_day parameter to search.php, which reveals the installation path in an error message.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/54235 | vdb entry |
http://www.morningstarsecurity.com/advisories/MORNINGSTAR-2009-02-CuteNews.txt | exploit |
http://www.securityfocus.com/archive/1/507782/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/36971 | vdb entry exploit |