CVE-2009-3756

Kreotek Phpbms - Information Disclosure

Title source: rule
STIX 2.1

Description

phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in advancedsearch.php, and (4) choicelist.php, which reveals the installation path in an error message.

Exploits (1)

exploitdb WORKING POC VERIFIED
by eLwaux · textwebappsphp
https://www.exploit-db.com/exploits/9101

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/51652
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9101

Scores

EPSS 0.0367
EPSS Percentile 88.0%

Details

CWE
CWE-200
Status published
Products (1)
kreotek/phpbms 0.96
Published Oct 22, 2009
Tracked Since Feb 18, 2026