marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to obtain sensitive information via an invalid (1) file or (2) category parameter, which reveal the path in an error message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nukebookmarks | Nukebookmarks | 0.6 (including) | 0.6 (including) |