Phpwebsite · Phpwebsite · CVE-2005-0572
**Name of the Vulnerable Software and Affected Versions**
phpWebSite versions 0.10.0 and earlier
**Description**
The issue allows remote attackers to obtain sensitive information via an invalid `SEA search module` parameter, which reveals the path in a PHP error message.
**Recommendations**
For phpWebSite versions 0.10.0 and earlier, consider restricting access to the `index.php` file until a patch is available. As a temporary workaround, avoid using the `SEA search module` parameter in the affected API endpoint until the issue is resolved.