"evaluatorImpact":"Successful exploitation requires that \"magic_quotes_gpc\" is disabled.",
"descriptions":[
{
"lang":"en",
"value":"SonicBB 1.0 allows remote attackers to obtain sensitive information via the (1) by[] parameter to search.php, (2) p[] parameter to viewforum.php, and the (3) id parameter to (a) viewforum.php or (b) members.php, which reveal the installation path in the resulting error message."
},
{
"lang":"es",
"value":"SonicBB 1.0 permite a atacantes remotos obtener informaci\u00f3n sensible a trav\u00e9s del par\u00e1metro (1) by[] en search.php, par\u00e1metro (2)p[] en viewforum.php, y el par\u00e1metro (3)id en (a) viewforum.php o (b) members.php, el cual revela la ruta de instalaci\u00f3n en el mensaje de error resultado."