hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Help - Search - Member List - Calendar
Full Version: Full Path Disclosure Csfaq
GovernmentSecurity.org > The Archives > Exploit Articles
qcred11
Jun 28 2004, 05:45 PM
QUOTE


PROGRAM: csFAQ
  HOMEPAGE: http://www.cgiscript.net/
  BUG: Full path disclosure
  DATE: 23/05/2004
  AUTHOR: DarkBicho
         
-----------------------------------------------------------------------------------------------


1.- Affected software description:
    ------------------------------
    csFAQ An automated system for displaying FAQs (frequently asked
    questions) written by
    CGI Scripts.

2.- Description:
    ------------
    This vulnerability would allow a remote user to determine the full
    path to the web root directory and other potentially sensitive
    information.

    :.: Examples:


    http://www.attack.com/cgi-script/csFAQ/csF...ase=/.darkbicho



    /www/attack/cgi-script/csFAQ//%2f%2edarkbicho
    Content-type: text/html
    Software error:
    1 at csFAQ.cgi line 1117.

3.- SOLUTION:
    จจจจจจจจ
    Vendors were contacted many weeks ago and plan to release a fixed
    version soon.
    Check the PHP-NUKE website for updates and official release details.

4.- Greetings:
    ---------
    greetings to my Peruvian group swp, perunderforce and machado ;)
    "EL PISCO ES Y SERA PERUANO"

5.- Contact
    -------


    WEB: http://www.darkbicho.tk
    EMAIL: darkbicho_at_peru.com

This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.