_Request_Message.cfm in tmsPUBLISHER 3.3 allows remote attackers to obtain sensitive information via an invalid id argument to pagename.cfm, which reveals the installation path in an error message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tmspublisher | The_media_shoppe_berhad | 3.0 (including) | 3.0 (including) |
Tmspublisher | The_media_shoppe_berhad | 3.3 (including) | 3.3 (including) |