post.php in XMB 1.9.2 allows remote attackers to obtain the installation path via an invalid fid parameter in a newthread action.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Xmb |
Xmb_forum |
1.9.2 (including) |
1.9.2 (including) |
Xmb |
Xmb_forum |
1.9.3 (including) |
1.9.3 (including) |
References