Description
DCP-Portal 3.7 through 4.5 allows remote attackers to obtain the physical path of the server via (1) a direct request to add_user.php, or via an invalid new_language parameter in (2) contents.php, (3) categories.php, or (4) files.php, which leaks the path in an error message.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2002-0279 | DCP-Portal 3.7 through 4.5 allows remote attackers to obtain the physical path of the server via (1) a direct request to add_user.php, or via an invalid new_language parameter in (2) contents.php, (3) categories.php, or (4) files.php, which leaks the path in an error message. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T02:42:28.624Z
Reserved: 2002-05-01T00:00:00.000Z
Link: CVE-2002-0282
No data.
Status : Modified
Published: 2002-05-31T04:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2002-0282
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD