blocker_query.php in Protector System 1.15b1 for PHP-Nuke allows remote attackers to gain sensitive information via a string in the portNum parameter, which reveals the full path in an error message.Referenceshttp://www.securityfocus.com/bid/10206https://exchange.xforce.ibmcloud.com/vulnerabilities/15963http://marc.info/?l=bugtraq&m=108276299810121&w=2http://www.waraxe.us/index.php?modname=sa&id=25http://protector.warcenter.se/article-53--0-0.html