myWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached through index.php; (2) a direct request to common.php; and (3) a mode array parameter in the query string to login.php, which reveal the installation path in various error messages.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2008-07-09T00:00:00Z
Updated: 2024-09-16T20:42:39.488Z
Reserved: 2007-07-10T00:00:00Z
Link: CVE-2007-3650
Vulnrichment
No data.
NVD
Status : Modified
Published: 2008-07-09T00:41:00.000
Modified: 2024-11-21T00:33:44.770
Link: CVE-2007-3650
Redhat
No data.