CVE
- Id
- 4674
- CVE No.
- CVE-2002-0282
- Status
- Candidate
- Description
- DCP-Portal 3.7 through 4.5 allows remote attackers to obtain the physical path of the server via (1) a direct request to add_user.php, or via an invalid new_language parameter in (2) contents.php, (3) categories.php, or (4) files.php, which leaks the path in an error message.
- Phase
- Modified (20050710)
- Votes
- ACCEPT(2) Cole, Frech | NOOP(4) Armstrong, Cox, Foat, Wall
- Comments