BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php, which includes the pathname in the source of the resulting HTML.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Badblue | Working_resources_inc. | 2.40 (including) | 2.40 (including) |