Description
PrestaShop 1.4.0.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by product-sort.php and certain other files.
Remediation
References
Related Vulnerabilities
Mailman Improper Restriction of Excessive Authentication Attempts Vulnerability (CVE-2021-42096)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-1686)
Moodle Improper Input Validation Vulnerability (CVE-2006-4936)
Oracle Application Server Other Vulnerability (CVE-2007-1609)