wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted request.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://websecurity.com.ua/2628/ | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/74320 | vdb entry |