Description
index.php in Aardvark Topsites PHP 5.2.0 and earlier allows remote attackers to obtain sensitive information via a nonexistent account name in the u parameter in a rate action, which reveals the installation path in an error message.
Affected products
- avatic / aardvark_topsites_php5.2.0
- avatic / aardvark_topsites_php4.0.2 – 4.0.2
- avatic / aardvark_topsites_php4.1.1 – 4.1.1
- avatic / aardvark_topsites_php4.2.2 – 4.2.2
- avatic / aardvark_topsites_php5 – 5
- avatic / aardvark_topsites_php5.0.3 – 5.0.3
- avatic / aardvark_topsites_php5.1.2 – 5.1.2