Korean
<< Back
VID 21325
Severity 20
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The PowerPortal installed on the Web server is vulnerable to a Path Disclosure Vulnerability.
PowerPortal is a popular content management system for Unix-based platforms, written in PHP. The versions 1.x of PowerPortal have a Path Disclosure Vulnerability. By sending the following URL:

http://[target_server]modules/gallery/resize.php
http://[target_server]/power/modules.php?name=gallery&files=darkbicho

a remote attacker could cause PowerPortal to return an error messages that discloses the full path of the Web root directory. A remote attacker can use this information to perform further attack.

* References:
http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0905.html

* Platforms Affected:
PowerPortal 1.x
Unix Any version
Recommendation No upgrade or patch available as of June 2014. Contact to your vendor for this vulnerability.
Related URL CVE-2004-0662 (CVE)
Related URL 10622 (SecurityFocus)
Related URL 16529 (ISS)