CitySoft Community Enterprise 4.x allows remote attackers to obtain the full path of the server via an invalid (1) fuseaction parameter to index.cfm and (2) documentid parameter to document/docWindow.cfm.
Link | Tags |
---|---|
http://secunia.com/advisories/18145 | third party advisory |
http://pridels0.blogspot.com/2005/12/community-enterprise-4x-multiple-vuln.html | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/23822 | vdb entry |
http://www.osvdb.org/21857 | vdb entry |
http://www.osvdb.org/21858 | vdb entry |