PivotX prior to 2.2.2 allows remote malicious users to obtain sensitive information via a direct request to (1) includes/ping.php and (2) includes/spamping.php, which reveals the installation path in an error message.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
pivotx pivotx 2.2.2 |