| VID |
21325 |
| Severity |
20 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The PowerPortal installed on the Web server is vulnerable to a Path Disclosure Vulnerability. PowerPortal is a popular content management system for Unix-based platforms, written in PHP. The versions 1.x of PowerPortal have a Path Disclosure Vulnerability. By sending the following URL:
http://[target_server]modules/gallery/resize.php http://[target_server]/power/modules.php?name=gallery&files=darkbicho a remote attacker could cause PowerPortal to return an error messages that discloses the full path of the Web root directory. A remote attacker can use this information to perform further attack.
* References: http://archives.neohapsis.com/archives/fulldisclosure/2004-06/0905.html
* Platforms Affected: PowerPortal 1.x Unix Any version |
| Recommendation |
No upgrade or patch available as of June 2014. Contact to your vendor for this vulnerability. |
| Related URL |
CVE-2004-0662 (CVE) |
| Related URL |
10622 (SecurityFocus) |
| Related URL |
16529 (ISS) |
|