Path Disclosure Vulnerability http://crm.******.com

Disclosed: 2019-04-05 09:25:05 By b4a1d31dd4acbccc47b8072 To unikrn
Low
Vulnerability Details
Hello, there is a path discovery on the server. https://crm.unikrn.com/plugins/MauticZapierBundle/MauticZapierBundle.php https://crm.unikrn.com/plugins/MauticCloudStorageBundle/MauticCloudStorageBundle.php and other scripts at https://crm.unikrn.com/plugins/*/*.php . As an option to eliminate the error, you can write the following code in the file .htaccess : error_reporting(0); ## Impact that will help the attacker to gather more information about your server. Such as local folder location by script on "crm"
Actions
View on HackerOne
Report Stats
  • Report ID: 503804
  • State: Closed
  • Substate: resolved
  • Upvotes: 12
Share this report