popup.php in EasyPHPCalendar before 6.2.8 allows remote attackers to obtain sensitive information via an invalid ev parameter, which reveals the full pathname of the web server in a PHP error message. Version 6.2.8 and above are fixed.
Publication date: Tue, 12 Apr 2005 09:00:00 +0000