vendor:
4images
by:
High-Tech Bridge SA Security Research Lab
3.3
CVSS
LOW
Path disclosure
200
CWE
Product Name: 4images
Affected Version From: 1.7.2009
Affected Version To: 1.7.2009
Patch Exists: YES
Related CWE: N/A
CPE: 4images
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
Multiple Path Disclousure in 4images
The vulnerability exists due to failure in the "includes/page_header.php" script, it's possible to generate an error that will reveal the full path of the script. A remote user can determine the full path to the web root directory and other potentiall sensitive information.
Mitigation:
Upgrade to the most recent version