Bytehoard Files.INC.PHP Root Directory Disclosure Vulnerability
BID:8910
Info
Bytehoard Files.INC.PHP Root Directory Disclosure Vulnerability
| Bugtraq ID: | 8910 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2003 12:00AM |
| Updated: | Oct 28 2003 12:00AM |
| Credit: | Discovery credited to Chris Sharp. |
| Vulnerable: |
Bytehoard Bytehoard 0.71 Bytehoard Bytehoard 0.7 |
| Not Vulnerable: | |
Discussion
Bytehoard Files.INC.PHP Root Directory Disclosure Vulnerability
Because of an issue in the files.inc.php, it is possible to view the contents of the web root directory. An attacker could exploit this issue to gain sensitive information about hosts, and potentially launch more directed attacks.
Because of an issue in the files.inc.php, it is possible to view the contents of the web root directory. An attacker could exploit this issue to gain sensitive information about hosts, and potentially launch more directed attacks.
Exploit / POC
Bytehoard Files.INC.PHP Root Directory Disclosure Vulnerability
This vulnerability may be exploited with a web browser.
This vulnerability may be exploited with a web browser.
Solution / Fix
Bytehoard Files.INC.PHP Root Directory Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Bytehoard Files.INC.PHP Root Directory Disclosure Vulnerability
References:
References:
- Bytehoard Homepage (Bytehoard)