Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wp6p-588g-vjc9

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Photostand 1.2.0 allows remote attackers to obtain sensitive information via a ' (quote) character in (1) a PHPSESSID cookie or (2) the id parameter in an article action in index.php, which reveal the path in various error messages.

Photostand 1.2.0 allows remote attackers to obtain sensitive information via a ' (quote) character in (1) a PHPSESSID cookie or (2) the id parameter in an article action in index.php, which reveal the path in various error messages.

EPSS

Процентиль: 68%
0.00574
Низкий

Связанные уязвимости

nvd
почти 19 лет назад

Photostand 1.2.0 allows remote attackers to obtain sensitive information via a ' (quote) character in (1) a PHPSESSID cookie or (2) the id parameter in an article action in index.php, which reveal the path in various error messages.

EPSS

Процентиль: 68%
0.00574
Низкий