Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) header.php, (2) contact.php, or (3) forum_extender.php, which reveals the path in an error message.
| Software | From | Fixed in |
|---|---|---|
| npds / npds | - | 5.10.x |
| npds / npds | 4.8 | 4.8.x |