The faq section in PostNuke 0.764 allows remote attackers to obtain sensitive information (the full path) via "unvalidated output" in FAQ/index.php, possibly involving an undefined id_cat variable.
References
Configurations
Information
Published : 2007-01-19 15:28
Updated : 2008-11-12 22:31
NVD link : CVE-2007-0385
Mitre link : CVE-2007-0385
JSON object : View
CWE
Products Affected
postnuke_software_foundation
- postnuke