article.php in PHP FirstPost 0.1 allows allows remote malicious users to obtain the full pathname of the server via an invalid post number in the post parameter, which leaks the pathname in an error message.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
php firstpost php firstpost 0.1 |