Medium
CVSS 5.0
Overview
HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message.
HTTP Commander 4.0 allows remote attackers to obtain sensitive information via a...
HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: