list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.
                
            References
                    | Link | Resource | 
|---|---|
| http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html | Exploit Vendor Advisory | 
| http://www.securityfocus.com/bid/11283 | |
| http://secunia.com/advisories/12695 | Patch Vendor Advisory | 
| http://securitytracker.com/id?1011463 | |
| http://marc.info/?l=bugtraq&m=109655691512298&w=2 | 
Configurations
                    Information
                Published : 2004-12-30 21:00
Updated : 2016-10-17 19:56
NVD link : CVE-2004-1565
Mitre link : CVE-2004-1565
JSON object : View
CWE
                Products Affected
                w-agora
- w-agora


