videos.php in PHPDirector 0.21 and earlier allows remote attackers to obtain sensitive information via an empty value of the id[] parameter, which reveals the path in an error message.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Phpdirector |
Phpdirector |
* |
0.21 (including) |
References