index.php in Rhadrix If-CMS, possibly 1.01 and 2.07, allows remote malicious users to obtain the full path of the web server via empty (1) rns[] or (2) pag[] arguments, which reveals the path in an error message.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
rhadrix if-cms 1.01 |
||
rhadrix if-cms 2.07 |