Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

DCP-Portal System Information Path Disclosure Vulnerability

DCP-Portal is a content management system which enables various web based updates. It enables an admin to remotely manage the entire site, and allows for members to submit news/content and reviews etc.

An issue has been reported in DCP-Portal, which could enable a remote user to reveal the absolute path to the web root.

Reportedly, invalid requests made to a host, will return an error message including the path to the web root.







 

Privacy Statement
Copyright 2008, SecurityFocus