Description
XOOPS 2.5.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/system/xoops_version.php and certain other files.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Mailto Links-Manage Email Links Cross-Site Scripting (2.0.1)
WordPress Plugin Secure HTML5 Video Player Cross-Site Scripting (3.3)
WordPress Plugin EME Sync Facebook Events Unspecified Vulnerability (1.0.38)
WordPress Plugin Accept Donations with PayPal Cross-Site Request Forgery (1.3.3)