Exploit WebTrends Reporting Center 6.1 Management Interface - Full Path Disclosure

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
23559
Проверка EDB
  1. Пройдено
Автор
OLIVER KAROW
Тип уязвимости
REMOTE
Платформа
WINDOWS
CVE
cve-2004-2748
Дата публикации
2004-01-20
Код:
source: https://www.securityfocus.com/bid/9460/info

The WebTrends Reporting Center management interface discloses installation path information when an invalid argument for an interface URI parameter is requested. This information may permit an attacker to enumerate the layout of the underlying file system of the host.

This issue was reported for version 6.1a of the software running on Microsoft Windows. Other platforms and versions may also be affected.

http://www.example.com:1099/viewreport.pl?profileid=dontexist
 
Источник
www.exploit-db.com

Похожие темы