Stellar Docs 1.2 - Full Path Disclosure
Author: G00db0y
type: webapps
platform: php
port:
date_added: 2003-08-11
date_updated: 2012-11-29
verified: 1
codes: OSVDB-2396
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/8385/info
Stellar Docs will disclose path information in an error page in response to a request for an invalid request for a web resource. This could disclose information that could be useful in further attacks against the system. It should be noted the error output indicates that a database function has failed, which may be due to a more serious issue, such as SQL injection.
http://www.example.com/pathofstellardocs/data/fetch.php?page='