Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

MRTG Configuration Generator Path Disclosure Vulnerability

MRTG Configuration Generator is a configuration file generator for devices being monitored on a network.

A vulnerability has been reported in mrtg.cgi that could allow a malicious user to view the full path to the web root.

Reportedly, if a user submits a HTTP request to a host containing unusual characters, the server will return an error page containing the path to the web root.







 

Privacy Statement
Copyright 2009, SecurityFocus