CVE-2006-4907 Information

Description

OSU 3.11alpha and 3.10a allows remote attackers to obtain sensitive information via a URL to a non-existent file which displays the web root path in the resulting error message.

Reference

http://secunia.com/advisories/22016 http://securityreason.com/securityalert/1602 http://www.securityfocus.com/archive/1/446372/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/29031

Share on: