xs_edit.php in the phpBB eXtreme Styles module 2.2.1 and earlier allows remote attackers to obtain the installation path of the application via an invalid viewbackup parameter.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Phpbb_extreme_styles | Phpbb_styles | * | 2.2.1 (including) |
References