CVE-2008-3060
08.10.2008, 00:00
V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php) and (2) an invalid session ID, which reveals the installation path in an error message.Enginsight
Vendor | Product | Version |
---|---|---|
v-webmail | v-webmail | 1.5.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References