Total vulnerabilities in the database
parser.php in phpCMS 1.2.1 and earlier, with non-stealth and debug modes enabled, allows remote attackers to gain sensitive information via an invalid file parameter, which reveals the web server's installation path.
Software | From | Fixed in |
---|---|---|
phpcms / phpcms | 1.2.1 | 1.2.1.x |
phpcms / phpcms | 1.1.9 | 1.1.9.x |
phpcms / phpcms | 1.2.0 | 1.2.0.x |