index.php in Rhadrix If-CMS, possibly 1.01 and 2.07, allows remote attackers to obtain the full path of the web server via empty (1) rns[] or (2) pag[] arguments, which reveals the path in an error message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
If-cms | Rhadrix | 1.01 (including) | 1.01 (including) |
If-cms | Rhadrix | 2.07 (including) | 2.07 (including) |