auction_my_auctions.php in phpbb-Auction 1.2m and earlier allows remote attackers to obtain sensitive information via an invalid mode parameter, which leaks the full path in a PHP error message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpbb-auction | Phpbb_group | 1.0m (including) | 1.0m (including) |
Phpbb-auction | Phpbb_group | 1.2m (including) | 1.2m (including) |