Exponent CMS 0.96.3 and later versions includes the full installation path in the base parameter to thumb.php, which allows remote attackers to obtain sensitive information. NOTE: this might be resultant from an absolute path traversal vulnerability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Exponent | Exponent | 0.94 (including) | 0.94 (including) |
Exponent | Exponent | 0.95 (including) | 0.95 (including) |
Exponent | Exponent | 0.96.1 (including) | 0.96.1 (including) |
Exponent | Exponent | 0.96.3 (including) | 0.96.3 (including) |
Exponent | Exponent | 0.96.4 (including) | 0.96.4 (including) |