Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Siteframe_cms | Siteframe | 3.2.1 (including) | 3.2.1 (including) |
Siteframe_cms | Siteframe | 3.2.2 (including) | 3.2.2 (including) |
Siteframe_cms | Siteframe | 3.2.3 (including) | 3.2.3 (including) |