The Gossamer Threads DBMan db.cgi CGI script allows remote malicious users to view environmental variables and setup information by referencing a non-existing database in the db parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
gossamer threads dbman 2.0.4 |