header-logo
Suggest Exploit
vendor:
phPay
by:
SecurityFocus
4.3
CVSS
MEDIUM
Path Disclosure
22
CWE
Product Name: phPay
Affected Version From: 02.02
Affected Version To: 02.02
Patch Exists: N/A
Related CWE: N/A
CPE: phPay
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002

phPay Path Disclosure Vulnerabilities

It has been reported that when specially crafted requests are made for many phPay pages and include files, an error condition may be triggered. The resulting error message may contain path information relative to the phPay installation and requested file.

Mitigation:

Ensure that error messages do not contain sensitive information.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/7309/info

phPay has been reported prone to multiple path disclosure vulnerabilities.

It has been reported that when specially crafted requests are made for many phPay pages and include files, an error condition may be triggered. The resulting error message may contain path information relative to the phPay installation and requested file.

Information gathered in this way may be used in further attacks against the system.

This vulnerability has been reported to affect phPay version 2.02. However, previous versions may also be affected. 

http://www.example.com/login.phpsess=your_session_id&abt=&new_lang=99999&caller=navlang

http://www.example.com/start.php?config=alper.inc.php