exploit-db-mirror/exploits/cgi/webapps/24285.txt
Offensive Security b4c96a5864 DB: 2021-09-03
28807 changes to exploits/shellcodes
2021-09-03 20:19:21 +00:00

11 lines
No EOL
654 B
Text

source: https://www.securityfocus.com/bid/10729/info
It is reported that Gattaca Server 2003 contains multiple path disclosure vulnerabilities.
By sending HTTP requests to Gattaca's web server, it is reportedly possible to cause the application to return error pages that contain the full installation path of the application and the web document root path.
These vulnerabilities could be used by an attacker to aid them in further attacks against the server.
Version 1.1.10.0 is reported vulnerable. Prior versions may also contain these vulnerabilities as well.
http://www.example.com/web.tmpl?HELPID=8000&TEMPLATE=skins//water&LANGUAGE=[whatever]