Sage 1.0 Beta 3 - Content Management System Full Path Disclosure
Author: euronymous
type: remote
platform: windows
port:
date_added: 2003-02-20
date_updated: 2012-10-27
verified: 1
codes: CVE-2003-1242;OSVDB-59658
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/6893/info
Sage Content Management System contains a path disclosure vulnerability. When a request is made for a module that does not exist, the returned error message contains the full path to the Sage installation directory.
Disclosed path information could be used to launch further attacks against the system.
http://hostname/?mod=some_thing&op=browse
http://hostname/?mod=node&nid=some_thing&op=view