index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attackers to obtain sensitive information via a crafted title parameter, which reveals the installation path in an error message.
- http://securityreason.com/securityalert/8183
- http://www.exploit-db.com/exploits/15645
No PoCs found on GitHub currently.