browse.php in Website Baker Project allows remote attackers to obtain sensitive data via (1) a directory that does not exist in the dir parameter or (2) a direct request to certain php files, which reveal the path in an error message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Website_baker | Website_baker | * | * |