Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Horde IMP 2.2.7 Path Disclosure Vulnerability

Horde IMP 2.2.7 scripts may disclose complete web server paths.

Requests for the following cause an error message to be displayed:

/poppassd.php3
/login.php3?reason=chpass2
/spelling.php3
/ldap.search.php3?ldap_serv=nonsense

Included in the error message is the full path on the web server to the script requested.







 

Privacy Statement
Copyright 2009, SecurityFocus