Description
OpenCart 1.4.9.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by system/startup.php and certain other files.
Remediation
References
Related Vulnerabilities
WordPress Plugin WebEngage Feedback, Survey and Notification Cross-Site Scripting (2.0.0)
Jetty Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2024-8184)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-2272)
WordPress Plugin Featured Content 'param' Parameter Cross-Site Scripting (0.0.1)
WordPress Plugin GiveWP-Donation and Fundraising Platform Cross-Site Request Forgery (2.25.2)