FloosieTek FTGatePro 1.22 - Mail Server Full Path Disclosure

EDB-ID:

23091

CVE:

N/A


Author:

Ziv Kamir

Type:

remote


Platform:

Windows

Date:

2003-09-02


source: https://www.securityfocus.com/bid/8527/info

FloosieTek FTGatePro Mail Server may disclose its installation path to remote attackers. This information could be useful when mounting further attacks against the system.

This issue exists in the web administrative interface, which listens on port 8089 by default. 

http://www.example.com:8089/utility/wmsecurity.fts