Escapade Scripting Engine PAGE Parameter Path Disclosure Vulnerability
BID:8574
Info
Escapade Scripting Engine PAGE Parameter Path Disclosure Vulnerability
| Bugtraq ID: | 8574 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 09 2003 12:00AM |
| Updated: | Sep 09 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Bahaa Naamneh <[email protected]>. |
| Vulnerable: |
Squished Mosquito Escapade 0.2.1 Beta |
| Not Vulnerable: | |
Discussion
Escapade Scripting Engine PAGE Parameter Path Disclosure Vulnerability
Escapade is prone to a path disclosure vulnerability. It is possible to gain access to sensitive path information by issuing a request for an invalid resource, passed as a value for the PAGE parameter to the Escapade Scripting Engine.
Escapade is prone to a path disclosure vulnerability. It is possible to gain access to sensitive path information by issuing a request for an invalid resource, passed as a value for the PAGE parameter to the Escapade Scripting Engine.
Exploit / POC
Escapade Scripting Engine PAGE Parameter Path Disclosure Vulnerability
The following proof of concept has been supplied:
http://www.site.com/cgi-bin/esp?PAGE=!@#$%
The following proof of concept has been supplied:
http://www.site.com/cgi-bin/esp?PAGE=!@#$%