Jupiter CMS 1.1.5, when display_errors is enabled, allows remote attackers to obtain the full server path via a direct request to modules/online.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jupiter_cms | Jupiter_cms | 1.1.5 (including) | 1.1.5 (including) |