index.php in Rhadrix If-CMS, possibly 1.01 and 2.07, allows remote attackers to obtain the full path of the web server via empty (1) rns[] or (2) pag[] arguments, which reveals the path in an error message.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| If-cms | Rhadrix | 1.01 (including) | 1.01 (including) |
| If-cms | Rhadrix | 2.07 (including) | 2.07 (including) |