Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Muscat_empower |
Brightstation |
1.0 (including) |
1.0 (including) |
References