5
CVSSv2

CVE-2003-1242

Published: 31/12/2003 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Sage 1.0 b3 allows remote malicious users to obtain the root web server path via a URL request for a non-existent module, which returns the path in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

Exploits

source: wwwsecurityfocuscom/bid/6893/info Sage Content Management System contains a path disclosure vulnerability When a request is made for a module that does not exist, the returned error message contains the full path to the Sage installation directory Disclosed path information could be used to launch further attacks against the sy ...