Aprox Portal 3.0 - File Disclosure
Author: Zero X
type: webapps
platform: php
port:
date_added: 2004-01-31
date_updated: 2012-12-24
verified: 1
codes: CVE-2004-0237;OSVDB-10859
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/9540/info
Aprox Portal is prone to a vulnerability that may permit remote attackers to gain access to files that are readable by the hosting web server. These files may exist outside of the server root.
This could expose sensitive information that may be useful in further attacks against the host.
http://www.example.com/index.php?show=/etc/passwd