Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-835c-9q4x-rhwq

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

myEvent 1.6 allows remote attackers to obtain sensitive information via (1) a Log In action without a password to login.php, or an invalid (2) view[] or (3) monthno[] parameter to myevent.php, which reveals the path in various error messages.

myEvent 1.6 allows remote attackers to obtain sensitive information via (1) a Log In action without a password to login.php, or an invalid (2) view[] or (3) monthno[] parameter to myevent.php, which reveals the path in various error messages.

EPSS

Процентиль: 68%
0.00574
Низкий

Связанные уязвимости

nvd
больше 18 лет назад

myEvent 1.6 allows remote attackers to obtain sensitive information via (1) a Log In action without a password to login.php, or an invalid (2) view[] or (3) monthno[] parameter to myevent.php, which reveals the path in various error messages.

EPSS

Процентиль: 68%
0.00574
Низкий