eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in the lesson_info module to index.php, which reveals the installation path in an error message.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2013-01-24T01:00:00Z
Updated: 2024-09-17T03:12:28.563Z
Reserved: 2013-01-23T00:00:00Z
Link: CVE-2012-6515

No data.

Status : Deferred
Published: 2013-01-24T01:55:05.287
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-6515

No data.