The issue is triggered when input passed via the 'go' parameter to the frontend/derfer.php script is not properly sanitized, which discloses the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
Disclosure Timeline:
Disclosure Date :2013-01-13
Exploit Publish Date :2013-01-13
Vendor Solution Date :2013-01-23