14all.cgi 1.1p15 in mrtgconfig allows remote attackers to determine the physical path to the web root directory via a request with an invalid cfg parameter, which generates an error message that reveals the path.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/8070 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2002-01/0421.html | vendor advisory mailing list exploit |
http://online.securityfocus.com/archive/1/254278 | mailing list |
http://www.securityfocus.com/bid/4021 | vdb entry |