Home page logo
/

bugtraq logo Bugtraq mailing list archives

DotClear : Multiples Full Path Disclosure
From: Silitix () gmail com
Date: 22 Jul 2006 04:16:24 -0000

# DotClear : Multiples Full Path Disclosure
# Discovred By Silitix - Silitix_gmail_com
# www.Silitix.com

A remote user can access the files directly to cause the system to display 
an error message that indicates the full path of the server.

/ecrire/tools/blogroll/edit_cat.php
/ecrire/tools/blogroll/index.php
/ecrire/tools/blogroll/edit_link.php
/ecrire/tools/syslog/index.php
/ecrire/tools/thememng/index.php
/ecrire/tools/toolsmng/index.php
/ecrire/tools/utf8convert/index.php
/ecrire/inc/connexion.php
/inc/session.php
/inc/classes/class.blog.php
/inc/classes/class.blogcomment.php
/inc/classes/class.blogpost.php
/layout/append.php
/layout/class.xblog.php
/layout/class.xblogcomment.php
/layout/class.xblogpost.php
/themes/default/form.php
/themes/default/list.php
/themes/default/post.php
/themes/default/template.php


  By Date           By Thread  

Current thread:
  • DotClear : Multiples Full Path Disclosure Silitix (Jul 22)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault