Security Advisory

CVE-2006-5832

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2006-11-10 01:00:00
Last updated 2024-08-07 20:04:55
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server via certain requests to (1) public/code/cp_dpage.php, possibly involving the aiocp_dp[] parameter, (2) public/code/cp_show_ec_products.php, possibly involving the order_field[] parameter, and (3) public/code/cp_show_page_help.php, possibly involving the hp[] parameter, which reveal the path in various error messages.