OSVDB ID: 24302

Title: Annuaire (Directory) /include/lang-en.php Direct Request Path Disclosure

Info

Disclosure

Mar 28, 2006

Discovery

Mar 22, 2006

Dates

Exploit

Mar 28, 2006

Solution

Unknown

Description

Annuaire (Directory) contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker makes a direct request to the /include/lang-en.php script, which will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.

Classification

Location: Remote / Network Access
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Exploit: Exploit Public
Disclosure: OSVDB Verified
OSVDB: Web Related

Solution

The vendor has discontinued this product and therefore has no patch or upgrade that mitigates this problem. It is recommended that an alternate software package be used in its place.

Products

www.brunox.org

Annuaire (Directory)

1.0

References

Credit

  • security curmudgeon - jerichoattrition.org - attrition.org


Direct URL: http://osvdb.org/24302