Path Disclosure Vulnerability

Disclosed: 2016-08-18 01:18:52 By jamalcom To iandunn-projects
Unknown
Vulnerability Details
Hey , I'm Jamal in this report i want to show you a Vulnerability Found It In basic-google-maps-placemarks Pugin Description: [#] Title : Path Disclosure Vulnerability [#] Status : Unfixed [#] Tested on : Firefox [#] Author : Jamal Eddine [#] Email : [email protected] [#] Discovered : 2014/05/04 [#] Report it : 2014/05/04 Target : http://www.foxyform.com/index.php?step[]=4%27 Description: Full Path Disclosure (FPD) vulnerability enable the attacker to see the path to the webroot/file. Certain vulnerabilities, such as using the load_file() (within a SQL Injection) query to view the page source, require the attacker to have the full path to the file they wish to view. Attack details: With the Inspect Elemenr of browser , we change the value in the form of any field of the plugin by addin the Empty array [] that's all and thank you so much
Actions
View on HackerOne
Report Stats
  • Report ID: 11729
  • State: Closed
  • Substate: not-applicable
  • Upvotes: 6
Share this report