parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to gain sensitive information via an invalid file parameter, which reveals the web servers installation path.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpcms | Phpcms | 1.1.9 (including) | 1.1.9 (including) |
Phpcms | Phpcms | 1.2.0 (including) | 1.2.0 (including) |
Phpcms | Phpcms | 1.2.1 (including) | 1.2.1 (including) |