12Planet Chat Server 2.5 - Error Message Installation Full Path Disclosure

EDB-ID:

22497

CVE:





Platform:

Multiple

Date:

2003-04-11


Become a Certified Penetration Tester

Enroll in Penetration Testing with Kali Linux , the course required to become an Offensive Security Certified Professional (OSCP)

GET CERTIFIED

source: https://www.securityfocus.com/bid/7355/info

When certain malformed URL requests are sent to a 12Planet Chat Server, the server's installation path may be revealed in the returned error message. This information could be used by a remote attacker to launch further attacks against the chat server.

http://www.victim.com:8080/qwe/qwe/qwe/index.html