Mozilla Bonsai 1.3 - Full Path Disclosure

Author: Stan Bubrouski
type: webapps
platform: cgi
port: 
date_added: 2002-08-20
date_updated: 2012-10-04
verified: 1
codes: CVE-2003-0153;OSVDB-5463;OSVDB-5462;OSVDB-5459
tags: 
aliases: 
screenshot_url: 
application_url: 

source: https://www.securityfocus.com/bid/5517/info

A path disclosure vulnerability has been reported in Mozilla Bonsai.

An attacker can exploit this vulnerability by making a malformed request to Bonsai. This causes Bonsai to return an error page to the requesting user. This error page will contain the absolute path information about the requested file.

/bonsai/cvsview2.cgi
/bonsai/multidiff.cgi
↑