CVE

CVE-2007-2800

Severity:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/06/2007
Last modified:
16/10/2018

Description

index.php in eTicket 1.5.5.1 and earlier allows remote attackers to obtain sensitive information via the (1) name[], (2) email[], (3) phone[], or (4) subject[] parameters, which reveals the installation path in the resulting error messages.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eticket:eticket:*:*:*:*:*:*:*:* 1.5.5.1 (including)