pafiledb.php in PaFileDB 3.1 allows remote attackers to gain sensitive information via an invalid or missing action parameter, which reveals the path in an error message when it cannot include a login.php script.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pafiledb | Php_arena | 3.1 (including) | 3.1 (including) |