Exploit eStore 1.0.1/1.0.2 - 'Settings.inc.php' Full Path Disclosure

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
22925
Проверка EDB
  1. Пройдено
Автор
BOSEN
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2003-0586
Дата публикации
2003-07-17
Код:
source: https://www.securityfocus.com/bid/8220/info

eStore is prone to a path disclosure vulnerability.

It has been reported that a remote attacker may make a direct HTTP request for an eStore include script and in doing so trigger an error. The resulting error message will disclose potentially sensitive installation path information to the remote attacker.

http://www.example.com/admin/settings.inc.php
 
Источник
www.exploit-db.com

Похожие темы