HostAdmin Path Disclosure Vulnerability
BID:8401
Info
HostAdmin Path Disclosure Vulnerability
| Bugtraq ID: | 8401 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2003 12:00AM |
| Updated: | Aug 12 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to G00db0y <[email protected]>. |
| Vulnerable: |
Dreamcost.com HostAdmin 0 |
| Not Vulnerable: | |
Discussion
HostAdmin Path Disclosure Vulnerability
HostAdmin is prone to a path disclosure vulnerability. Passing invalid data to the HostAdmin site will cause an error message to be displayed, which contains installation path information.
HostAdmin is prone to a path disclosure vulnerability. Passing invalid data to the HostAdmin site will cause an error message to be displayed, which contains installation path information.
Exploit / POC
HostAdmin Path Disclosure Vulnerability
The following proof of concept has been supplied:
http://www.example.com/pathofhostadmin/?page='
The following proof of concept has been supplied:
http://www.example.com/pathofhostadmin/?page='
References
HostAdmin Path Disclosure Vulnerability
References:
References:
- HostAdmin Homepage (dreamcost)
- ZH2003-23SA (security advisory): HostAdmin Path Disclosure (G00db0y
)