5
CVSSv2

CVE-2002-0266

Published: 29/05/2002 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Thunderstone Texis CGI script allows remote malicious users to obtain the full path of the web root via a request for a nonexistent file, which generates an error message that includes the full pathname.

Vulnerable Product Search on Vulmon Subscribe to Product

thunderstone software texis 3.0

Exploits

source: wwwsecurityfocuscom/bid/4035/info A vulnerability in TEXIS allows an attacker to view the full path to the web root If the attacker submits an HTTP request for an invalid path, the server will return an error page containing the path to the web root System information may also be revealed Versions prior to TEXIS 40310494069 ...