EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.
| Software | From | Fixed in |
|---|---|---|
| phome / empirecms | 6.6 | 6.6.x |
| phome / empirecms | 7.0 | 7.0.x |
| phome / empirecms | 7.2 | 7.2.x |
| dedecms / dedecms | 5.7 | 5.7.x |