index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to obtain the full server path via an invalid VDNS_Sessid parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vegadns | Vegadns | 0.8.1 (including) | 0.8.1 (including) |
Vegadns | Vegadns | 0.9.8 (including) | 0.9.8 (including) |