index.php in Aardvark Topsites PHP 5.2.1 and earlier...
Moderate severity
Unreviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Apr 9, 2025
Description
Published by the National Vulnerability Database
Jul 2, 2009
Published to the GitHub Advisory Database
May 2, 2022
Last updated
Apr 9, 2025
index.php in Aardvark Topsites PHP 5.2.1 and earlier allows remote attackers to obtain sensitive information via a negative integer value for the start parameter in a search action, which reveals the installation path in an error message.
References