AOH :: Web :: Blogs :: B06-3803.HTM

DotClear : Multiples Full Path Disclosure

DotClear : Multiples Full Path Disclosure
DotClear : Multiples Full Path Disclosure



# DotClear : Multiples Full Path Disclosure=0D
# Discovred By Silitix - Silitix_gmail_com=0D
# www.Silitix.com=0D 
=0D
A remote user can access the files directly to cause the system to display =0D
an error message that indicates the full path of the server.=0D
=0D
/ecrire/tools/blogroll/edit_cat.php=0D
/ecrire/tools/blogroll/index.php=0D
/ecrire/tools/blogroll/edit_link.php=0D
/ecrire/tools/syslog/index.php=0D
/ecrire/tools/thememng/index.php=0D
/ecrire/tools/toolsmng/index.php=0D
/ecrire/tools/utf8convert/index.php=0D
/ecrire/inc/connexion.php=0D
/inc/session.php=0D
/inc/classes/class.blog.php=0D
/inc/classes/class.blogcomment.php=0D
/inc/classes/class.blogpost.php=0D
/layout/append.php=0D
/layout/class.xblog.php=0D
/layout/class.xblogcomment.php=0D
/layout/class.xblogpost.php=0D
/themes/default/form.php=0D
/themes/default/list.php=0D
/themes/default/post.php=0D
/themes/default/template.php

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2009 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.