CVE-2014-2009
Beschrijving NL
De mPAY24-betalingsmodule vóór 1.6 voor PrestaShop stelt externe aanvallers in staat om inloggegevens, het installatiepad en andere gevoelige informatie te verkrijgen via een direct verzoek aan api/curllog.log.
Origineel (Engels) tonen
The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path, and other sensitive information via a direct request to api/curllog.log.