Arab Portal 2.0 allows remote attackers to obtain sensitive information via a long (1) username or (2) password, which reveals the path in an error message when the undefined errmsg function is called.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Arab_portal | Arab_portal | 2.0 (including) | 2.0 (including) |