Sage Content Management System Path Disclosure Vulnerability
BID:6893
Info
Sage Content Management System Path Disclosure Vulnerability
| Bugtraq ID: | 6893 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 20 2003 12:00AM |
| Updated: | Feb 20 2003 12:00AM |
| Credit: | Discovery is credited to euronymous <[email protected]>. |
| Vulnerable: |
Sage Sage 1.0 beta 3 |
| Not Vulnerable: | |
Discussion
Sage Content Management System Path Disclosure Vulnerability
Sage Content Management System contains a path disclosure vulnerability. When a request is made for a module that does not exist, the returned error message contains the full path to the Sage installation directory.
Disclosed path information could be used to launch further attacks against the system.
Sage Content Management System contains a path disclosure vulnerability. When a request is made for a module that does not exist, the returned error message contains the full path to the Sage installation directory.
Disclosed path information could be used to launch further attacks against the system.
Exploit / POC
Sage Content Management System Path Disclosure Vulnerability
The following proof of concepts were provided:
http://hostname/?mod=some_thing&op=browse
http://hostname/?mod=node&nid=some_thing&op=view
The following proof of concepts were provided:
http://hostname/?mod=some_thing&op=browse
http://hostname/?mod=node&nid=some_thing&op=view
References
Sage Content Management System Path Disclosure Vulnerability
References:
References:
- Sage Home Page (Sage)
- XSS and Path Disclosure in Sage ("euronymous"
)