CVE-2010-4781

index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attackers to obtain sensitive information via a crafted title parameter, which reveals the installation path in an error message.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
enanocmsenano_cms
𝑥
≤ 1.1.7
enanocmsenano_cms
0.8.1
enanocmsenano_cms
0.8.2
enanocmsenano_cms
0.8.3
enanocmsenano_cms
0.8.4
enanocmsenano_cms
0.9.1
enanocmsenano_cms
0.9.2
enanocmsenano_cms
0.9.3
enanocmsenano_cms
1.0
enanocmsenano_cms
1.0.1
enanocmsenano_cms
1.0.2
enanocmsenano_cms
1.0.2b1:b1
enanocmsenano_cms
1.0.3
enanocmsenano_cms
1.0.4
enanocmsenano_cms
1.0.5
enanocmsenano_cms
1.0.6
enanocmsenano_cms
1.0.6:pl1
enanocmsenano_cms
1.0.6:pl2
enanocmsenano_cms
1.0.6:pl3
enanocmsenano_cms
1.1.1
enanocmsenano_cms
1.1.2
enanocmsenano_cms
1.1.3
enanocmsenano_cms
1.1.4
enanocmsenano_cms
1.1.5
enanocmsenano_cms
1.1.6
enanocmsenano_cms
1.1.7
enanocmsenano_cms
1.1.7:pl1
𝑥
= Vulnerable software versions