rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in which the ajaxbool value is manipulated to be true.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Xinhu | Rockoa | 2.1.9 (including) | 2.1.9 (including) |
References