WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl with an empty Profile parameter, which leaks the pathname in an error message.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/8865.php | vdb entry patch vendor advisory |
http://archives.neohapsis.com/archives/bugtraq/2002-04/0207.html | mailing list vendor advisory |
http://www.osvdb.org/10447 | vdb entry |
http://www.ngssoftware.com/advisories/wtr.txt |