An unspecified script in EVA-Web 2.1.2 and previous versions, probably index.php, allows remote malicious users to obtain the full path of the web server via invalid (1) perso or (2) aide parameters.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
eva-web eva-web |