list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.
References
Link | Resource |
---|---|
http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html | Exploit Vendor Advisory |
http://www.securityfocus.com/bid/11283 | |
http://secunia.com/advisories/12695 | Patch Vendor Advisory |
http://securitytracker.com/id?1011463 | |
http://marc.info/?l=bugtraq&m=109655691512298&w=2 |
Configurations
Information
Published : 2004-12-30 21:00
Updated : 2016-10-17 19:56
NVD link : CVE-2004-1565
Mitre link : CVE-2004-1565
JSON object : View
CWE
Products Affected
w-agora
- w-agora