Skip to main content

CVE detail

CVE-2010-2859

news.php in SimpNews 2.47.3 and earlier allows remote attackers to obtain sensitive information via an invalid lang parameter, which reveals the installation path in an error message.

CVSS 5.0 · Medium