WoltLab Community Framework (WCF) 1.0.6 in WoltLab Burning Board 3.0.5 allows remote attackers to obtain the full path via invalid (1) page and (2) form parameters, which leaks the path from an exception handler when a valid class cannot be found.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://secunia.com/advisories/29719 | third party advisory vendor advisory |
http://www.securityfocus.com/archive/1/490782/100/0/threaded | mailing list |
http://www.securityfocus.com/bid/28678 | vdb entry |
http://archives.neohapsis.com/archives/fulldisclosure/2008-04/0161.html | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41713 | vdb entry |
http://www.securityfocus.com/archive/1/490560/100/0/threaded | mailing list |
http://lists.grok.org.uk/pipermail/full-disclosure/2008-April/061271.html | mailing list |