BugTraq
Fullpath disclosure in roundcube webmail Dec 17 2005 07:43PM
king_purba yahoo co uk
I try this request in my mailbox
http://xxxx.com/roundcube/?_auth=3Dcf559dcf52d8801ccd51cd1f3ba3eca08d1b0
bce=
&_task=3Dma%60il
then roundcube shows this warning

**PHP Error in /usr/local/apache2/htdocs/roundcube/index.php (301)*:* Invalid
request failed/file not found

The requested page was not found!
Please contact your server-administrator.

*Failed request:*
http://xxxx.com/roundcube/?_auth=3Dcf559dcf52d8801ccd51cd1f3ba3eca08d1b0
bce=
&_task=3Dma%60il

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus