FloosieTek FTGatePro 1.22 - Mail Server Full Path Disclosure

EDB-ID:

23091

CVE:

N/A

Author:

Ziv Kamir

Type:

remote

Platform:

Windows

Published:

2003-09-02

source: http://www.securityfocus.com/bid/8527/info

FloosieTek FTGatePro Mail Server may disclose its installation path to remote attackers. This information could be useful when mounting further attacks against the system.

This issue exists in the web administrative interface, which listens on port 8089 by default. 

http://www.example.com:8089/utility/wmsecurity.fts