V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php) and (2) an invalid session ID, which reveals the installation path in an error message.
Score: 3.0
Priority: P2 - Serious (High)
Score: 0.00294
Percentile:
0.52339
CVSS v2 Score: 5.0
Severity: