Description
Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page or (3) cat parameter to thumbnails.php, an invalid (4) page parameter to usermgr.php, or an invalid (5) newer_than or (6) older_than parameter to search.inc.php, which reveals the installation path in an error message.
Remediation
References
Related Vulnerabilities
WordPress Plugin Uploadify Integration Multiple Cross-Site Scripting Vulnerabilities (0.9.6)
WordPress Plugin Frontend File Manager Cross-Site Request Forgery (21.3)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2043)
Envoy Proxy Improper Certificate Validation Vulnerability (CVE-2022-21656)