CVE

Id
19469  
CVE No.
CVE-2006-3365  
Status
Candidate  
Description
V3 Chat allows remote attackers to obtain the installation path via (1) an invalid id parameter to mail/index.php or (2) membername parameter to messenger/online.php, which displays the path in an error page due to an incorrect SQL statement.  
Phase
Assigned (20060706)  
Votes
None (candidate not yet proposed)  
Comments