Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:25236
HistoryDec 06, 2010 - 12:00 a.m.

Path disclosure in Etomite

2010-12-0600:00:00
vulners.com
22

Vulnerability ID: HTB22711
Reference: http://www.htbridge.ch/advisory/path_disclosure_in_etomite.html
Product: Etomite
Vendor: http://www.etomite.org/ ( http://www.etomite.org/ )
Vulnerable Version: 1.1
Vendor Notification: 18 November 2010
Vulnerability Type: Path disclosure
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Low
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)

Vulnerability Details:
The vulnerability exists due to failure in the "/manager/frames/3.php" script, it's possible to generate an error that will reveal the full path of the script.
A remote user can determine the full path to the web root directory and other potentially sensitive information.

http://[host]/manager/frames/3.php