[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Path disclousure in MEGA PORTAL
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: Path disclousure in MEGA PORTAL
- From: bolok.boloke80@xxxxxxxxx
- Date: Mon, 2 May 2011 08:35:18 -0600
Product: MEGA PORTAL
Vendor: http://www.got.my
Demo: http://www.got.my/MEGA-PORTAL/
Vulnerability Type: Path disclosure
Risk level: medium
Credit: Hector.x90
Vulnerability Details:
A remote user can determine the full path to the web root directory and other
potentially sensitive information.
The following PoC is available:
http://[host]/themes/default/slideshow.php