Описание
PivotX before 2.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) includes/ping.php and (2) includes/spamping.php, which reveals the installation path in an error message.
Ссылки
- PatchVendor Advisory
- Patch
- Exploit
- PatchVendor Advisory
- Patch
- Exploit
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:pivotx:pivotx:2.2.2:*:*:*:*:*:*:*
EPSS
Процентиль: 51%
0.00283
Низкий
5 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
github
больше 3 лет назад
PivotX before 2.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) includes/ping.php and (2) includes/spamping.php, which reveals the installation path in an error message.
EPSS
Процентиль: 51%
0.00283
Низкий
5 Medium
CVSS2
Дефекты
CWE-200