CVE-2009-4254 Information
Feb 14, 2021
cve
Description
PowerPhlogger 2.2.5 allows remote attackers to obtain sensitive information via a direct request to (1) edCss.inc.php (2) foot.inc.php (3) get_csscolors.inc.php (4) head.inc.php (5) head_stuff.inc.php (6) loglist.inc.php and (7) pphlogger_send.inc.php in include/ which reveals the installation path in an error message.
Reference
http://www.websecurity.com.ua/1845 https://exchange.xforce.ibmcloud.com/vulnerabilities/54543
Share on: