PHPOutsourcing Zorum 3.4 - Full Path Disclosure

EDB-ID:

23018




Platform:

PHP

Date:

2003-08-11


source: https://www.securityfocus.com/bid/8396/info

A vulnerability has been reported in Zorum message board software that allows a remote attacker to send a malformed HTTP request resulting in a disclosure of the installation path.

This issue may allow an attacker to gain knowledge of the file system in order to mount further attacks against the host.

http://www.example.com/forum/index.php?method=userfunctions&'list=secmenu&