News Wizard 2.0 - Full Path Disclosure



EKU-ID: 28474 CVE: OSVDB-ID:
Author: G00db0y Published: 2003-08-11 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/8389/info

News Wizard will disclose path information in an error page in response to a request for an invalid request for a web resource. This could disclose information that could be useful in further attacks against the system.

http://www.example.com/path/nw/article.php?id='