[] NeoSense

Mozilla Bonsai 1.3 - Full Path Disclosure

Author: Stan Bubrouski
type: webapps
platform: cgi
port: 
date_added: 2002-08-20 
date_updated: 2012-10-04 
verified: 1 
codes: CVE-2003-0153;OSVDB-5463;OSVDB-5462;OSVDB-5459 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/5517/info

A path disclosure vulnerability has been reported in Mozilla Bonsai.

An attacker can exploit this vulnerability by making a malformed request to Bonsai. This causes Bonsai to return an error page to the requesting user. This error page will contain the absolute path information about the requested file.

/bonsai/cvsview2.cgi
/bonsai/multidiff.cgi