[] NeoSense

PHPOutsourcing Zorum 3.4 - Full Path Disclosure

Author: Zone-h Security Team
type: webapps
platform: php
port: 
date_added: 2003-08-11 
date_updated: 2012-11-30 
verified: 1 
codes: CVE-2003-1089;OSVDB-3609 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/8396/info

A vulnerability has been reported in Zorum message board software that allows a remote attacker to send a malformed HTTP request resulting in a disclosure of the installation path.

This issue may allow an attacker to gain knowledge of the file system in order to mount further attacks against the host.

http://www.example.com/forum/index.php?method=userfunctions&'list=secmenu&