Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to obtain sensitive information (the full path) via unspecified vectors, probably involving direct requests to certain PHP scripts in tmpl/ directories.
| Software | From | Fixed in |
|---|---|---|
| Joomla / joomla | 1.5.0_rc1 | 1.5.0_rc1.x |
| Joomla / joomla | 1.5.0_beta2 | 1.5.0_beta2.x |
| Joomla / joomla | 1.5.0_beta | 1.5.0_beta.x |