CVE-2005-4214

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
14/12/2005
Last modified:
19/10/2018

Description

phpCOIN 1.2.2 allows remote attackers to obtain the installation path via a direct request to config.php, which leaks the path in an error message because the _CCFG['_PKG_PATH_DBSE'] variable is not defined.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:coinsoft_technologies:phpcoin:1.2.2:*:*:*:*:*:*:*