PHPChain 1.0 and earlier allows remote attackers to obtain the installation path via invalid values of the catid parameter to (1) settings.php or (2) cat.php, as demonstrated by XSS manipulations.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-05-14T23:00:00

Updated: 2024-08-07T13:49:57.065Z

Reserved: 2007-05-14T00:00:00

Link: CVE-2007-2670

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-05-14T23:19:00.000

Modified: 2024-11-21T00:31:22.260

Link: CVE-2007-2670

cve-icon Redhat

No data.