CVE-2008-6981 Information

Description

index.php in phpAdultSite CMS possibly 2.3.2 allows remote attackers to obtain the full installation path via an invalid results_per_page parameter which leaks the path in an error message. NOTE: this issue might be resultant from a separate SQL injection vulnerability.

Reference

http://www.davidsopas.com/2008/09/phpadult-cms-exploit/ http://www.securityfocus.com/archive/1/496069/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/44924

Share on: