DLGuard 4.5 allows remote attackers to obtain the installation path via the c parameter to index.php.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2209
Reference (s):
- BID:72685
- URL: http://www.securityfocus.com/bid/72685
- FULLDISC:20150218 DLGuard Full Path Disclosure (Information Leakage) Security Vulnerabilities
- URL: http://seclists.org/fulldisclosure/2015/Feb/67
- http://tetraph.com/security/full-path-disclosure-vulnerability/dlguard-full-path-disclosure-information-leakage-security-vulnerabilities/

