Total vulnerabilities in the database
All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server via certain requests to (1) public/code/cp_dpage.php, possibly involving the aiocp_dp[] parameter, (2) public/code/cp_show_ec_products.php, possibly involving the order_field[] parameter, and (3) public/code/cp_show_page_help.php, possibly involving the hp[] parameter, which reveal the path in various error messages.
Software | From | Fixed in |
---|---|---|
aiocp / aiocp | 1.3.005 | 1.3.005.x |
aiocp / aiocp | 1.3.003 | 1.3.003.x |
aiocp / aiocp | 1.3.006 | 1.3.006.x |
aiocp / aiocp | 1.3.000 | 1.3.000.x |
aiocp / aiocp | 1.3.002 | 1.3.002.x |
aiocp / aiocp | 1.3.001 | 1.3.001.x |
aiocp / aiocp | 1.3.004 | 1.3.004.x |
aiocp / aiocp | 1.3.007 | 1.3.007.x |