Chipmailer 1.09 allows remote attackers to obtain sensitive information via a direct request to php.php, which displays the output of the phpinfo function.
- http://marc.info/?l=bugtraq&m=115024576618386&w=2
No PoCs found on GitHub currently.