CVE-2006-2532 Information
Feb 14, 2021
cve
Description
stats.php in Destiney Rated Images Script 0.5.0 allows remote attackers to obtain the installation path via an invalid s parameter which displays the path in an error message. NOTE: this issue was originally claimed to be SQL injection but CVE analysis shows that the problem is related to an invalid value that prevents some variables from being set.
Reference
http://securityreason.com/securityalert/940 http://www.securityfocus.com/archive/1/434691/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/26603
Share on: