Mozilla Bonsai 1.3 - Full Path Disclosure
Author: Stan Bubrouski
type: webapps
platform: cgi
port:
date_added: 2002-08-20
date_updated: 2012-10-04
verified: 1
codes: CVE-2003-0153;OSVDB-5463;OSVDB-5462;OSVDB-5459
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/5517/info
A path disclosure vulnerability has been reported in Mozilla Bonsai.
An attacker can exploit this vulnerability by making a malformed request to Bonsai. This causes Bonsai to return an error page to the requesting user. This error page will contain the absolute path information about the requested file.
/bonsai/cvsview2.cgi
/bonsai/multidiff.cgi