MyTopix 1.2.3 allows remote attackers to obtain the installation path via an invalid hl parameter to index.php, which leads to path disclosure, possibly related to invalid SQL syntax.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mytopix | Jaia_interactive | 1.2.3 (including) | 1.2.3 (including) |