Thunderstone TEXIS 3.0 - Full Path Disclosure

EDB-ID:

21276


Author:

phinegeek

Type:

remote


Platform:

Multiple

Date:

2002-02-06


source: https://www.securityfocus.com/bid/4035/info

A vulnerability in TEXIS allows an attacker to view the full path to the web root.

If the attacker submits an HTTP request for an invalid path, the server will return an error page containing the path to the web root. System information may also be revealed.

Versions prior to TEXIS 4.03.1049406926 20030403 are vulnerable. 

http://www.example.com/texis/nonexistent/path/