post.php in x_atrix xGuestBook 1.02 allows remote attackers to obtain sensitive information via a request without the (1) user, (2) mail, (3) p, or (4) url parameter, which reveals the installation path in an error message.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2006-07-31T22:00:00
Updated: 2024-08-07T18:48:39.324Z
Reserved: 2006-07-31T00:00:00
Link: CVE-2006-3937
Vulnrichment
No data.
NVD
Status : Modified
Published: 2006-07-31T22:04:00.000
Modified: 2024-11-21T00:14:45.457
Link: CVE-2006-3937
Redhat
No data.