BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cachefalse query string to footer.php or (2) a direct request to pagination.php, which reveals the installation path in an error message.
Publication date: Fri, 25 Jul 2008 18:41:00 +0000