vendor:
phPay
by:
SecurityFocus
4.3
CVSS
MEDIUM
Path Disclosure
22
CWE
Product Name: phPay
Affected Version From: 02.02
Affected Version To: 02.02
Patch Exists: N/A
Related CWE: N/A
CPE: phPay
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
phPay Path Disclosure Vulnerabilities
It has been reported that when specially crafted requests are made for many phPay pages and include files, an error condition may be triggered. The resulting error message may contain path information relative to the phPay installation and requested file.
Mitigation:
Ensure that error messages do not contain sensitive information.