index.php in Open-Realty 2.3.4 allows remote attackers to obtain sensitive information (the full path) via an invalid listingID parameter in a listingview action.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Open-realty | Open-realty | 2.3.4 (including) | 2.3.4 (including) |
References