index.php in Aardvark Topsites PHP 5.2.1 and earlier allows remote attackers to obtain sensitive information via a negative integer value for the start parameter in a search action, which reveals the installation path in an error message.
Software | From | Fixed in |
---|---|---|
avatic / aardvark_topsites_php | - | 5.2.1.x |
avatic / aardvark_topsites_php | 4.0.2 | 4.0.2.x |
avatic / aardvark_topsites_php | 4.1.1 | 4.1.1.x |
avatic / aardvark_topsites_php | 4.2.2 | 4.2.2.x |
avatic / aardvark_topsites_php | 5 | 5.x |
avatic / aardvark_topsites_php | 5.0.3 | 5.0.3.x |
avatic / aardvark_topsites_php | 5.1.2 | 5.1.2.x |
avatic / aardvark_topsites_php | 5.2.0 | 5.2.0.x |