BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php, which includes the pathname in the source of the resulting HTML.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Badblue | Working_resources_inc. | 2.40 (including) | 2.40 (including) |