index.php in eTicket 1.5.5.1 and earlier allows remote attackers to obtain sensitive information via the (1) name[], (2) email[], (3) phone[], or (4) subject[] parameters, which reveals the installation path in the resulting error messages.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Eticket | Eticket | * | 1.5.5.1 (including) |