CVE-2018-10423

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
26/04/2018
Last modified:
30/10/2018

Description

mc-admin/post.php in MiniCMS 1.10 allows remote attackers to obtain a directory listing of the top-level directory of the web root via a link that becomes available after posting an article.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:1234n:minicms:1.10:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools