askSam Web Publisher 1.0 and 4.0 allows remote attackers to determine the full path to the web root directory via a request for a file that does not exist, which generates an error message that reveals the full path.
Link | Tags |
---|---|
http://online.securityfocus.com/archive/82/270970 | mailing list |
http://www.securityfocus.com/bid/4670 | vdb entry exploit |
http://www.ifrance.com/kitetoua/tuto/5holes4.txt | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/9004 | vdb entry |