The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to obtain sensitive information via an invalid feed parameter, which reveals the path in an error message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Joomla | Joomla | 1.0.7 (including) | 1.0.7 (including) |
Mambo | Mambo | 4.5.3h-h (including) | 4.5.3h-h (including) |