Stellar Docs 1.2 - Full Path Disclosure

EDB-ID:

23009

CVE:



Author:

G00db0y

Type:

webapps


Platform:

PHP

Date:

2003-08-11


source: https://www.securityfocus.com/bid/8385/info

Stellar Docs will disclose path information in an error page in response to a request for an invalid request for a web resource. This could disclose information that could be useful in further attacks against the system. It should be noted the error output indicates that a database function has failed, which may be due to a more serious issue, such as SQL injection.

http://www.example.com/pathofstellardocs/data/fetch.php?page='