exploit-db-mirror/exploits/windows/remote/22269.txt
Offensive Security b4c96a5864 DB: 2021-09-03
28807 changes to exploits/shellcodes
2021-09-03 20:19:21 +00:00

9 lines
No EOL
449 B
Text

source: https://www.securityfocus.com/bid/6893/info
Sage Content Management System contains a path disclosure vulnerability. When a request is made for a module that does not exist, the returned error message contains the full path to the Sage installation directory.
Disclosed path information could be used to launch further attacks against the system.
http://hostname/?mod=some_thing&op=browse
http://hostname/?mod=node&nid=some_thing&op=view