CVE

Id
33177  
CVE No.
CVE-2008-3060  
Status
Candidate  
Description
V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php) and (2) an invalid session ID, which reveals the installation path in an error message.  
Phase
Assigned (20080707)  
Votes
None (candidate not yet proposed)  
Comments