list.php in 4.1.6a w-Agora permette attaccanti remoti per rivelare il percorso completo attraverso una richiesta HTTP predisposta, eventualmente, di un parametro id valido. |
http://www.securityfocus.com/bid/11283 http://marc.info/?l=bugtraq&m=109655691512298&w=2 http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html http://securitytracker.com/id?1011463 http://secunia.com/advisories/12695 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1565 |
Vulnerabilità: CVE-2004-1565
