Thunderstone Texis CGI script allows remote malicious users to obtain the full path of the web root via a request for a nonexistent file, which generates an error message that includes the full pathname.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
thunderstone software texis 3.0 |