SonicBB 1.0 allows remote attackers to obtain sensitive information via the (1) by[] parameter to search.php, (2) p[] parameter to viewforum.php, and the (3) id parameter to (a) viewforum.php or (b) members.php, which reveal the installation path in the resulting error message.
References
Configurations
History
No history.
Information
Published : 2007-05-14 21:19
Updated : 2024-02-28 11:01
NVD link : CVE-2007-1901
Mitre link : CVE-2007-1901
CVE.ORG link : CVE-2007-1901
JSON object : View
Products Affected
sonicbb
- sonicbb
CWE