Description
LimeSurvey 1.90+ build9642-20101214 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/statistics.php and certain other files.
Remediation
References
Related Vulnerabilities
WordPress Plugin Erident Custom Login and Dashboard Cross-Site Request Forgery (3.4.1)
Drupal Core 9.4.x Security Bypass (9.4.0 - 9.4.2)
WordPress Plugin BulletProof Security Multiple Cross-Site Scripting Vulnerabilities (.48.9)
phpBB Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2007-5173)
Joomla Improper Authentication Vulnerability (CVE-2014-6632)