Required CVE Record Information
Description
plug.php in Land Down Under (LDU) 802 and earlier allows remote attackers to obtain sensitive information via an invalid (1) month or (2) year parameter, which reveals the path in an error message.
References 3 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- securityfocus.com: 20060427 Land Down Under 802 and below version Path Disclosure Vulnerability mailing-listx_transferred
- exchange.xforce.ibmcloud.com: landdownunder-monthyear-path-disclosure(26143) vdb-entryx_transferred
- securityreason.com: 814 third-party-advisoryx_transferred