Pixelpost 1.5 beta 1 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, which calls the phpinfo function. NOTE: the vendor has disputed some issues from the original disclosure, but due to the vagueness of the dispute, it is not clear whether the vendor is disputing this particular issue.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Pixelpost | Pixelpost | 1.4.3 (including) | 1.4.3 (including) |
| Pixelpost | Pixelpost | 1.5_beta1 (including) | 1.5_beta1 (including) |