browse.php in Website Baker Project allows remote attackers to obtain sensitive data via (1) a directory that does not exist in the dir parameter or (2) a direct request to certain php files, which reveal the path in an error message.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Website_baker | Website_baker | * | * |