CVE-2006-5832 Information
Feb 14, 2021
cve
Description
All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server via certain requests to (1) public/code/cp_dpage.php possibly involving the aiocp_dp[] parameter (2) public/code/cp_show_ec_products.php possibly involving the order_field[] parameter and (3) public/code/cp_show_page_help.php possibly involving the hp[] parameter which reveal the path in various error messages.
Reference
http://securityreason.com/securityalert/1839 http://sourceforge.net/project/shownotes.php?release_id=478370 http://www.securityfocus.com/archive/1/450701/100/0/threaded http://www.securityfocus.com/bid/20931 https://exchange.xforce.ibmcloud.com/vulnerabilities/30052
Share on: