Path Disclosure Vulnerability in eNdonesia 8.2
CVE-2003-1316

Currently unrated

Key Information:

Vendor

eNdonesia

Status
Vendor
CVE Published:
31 December 2003

What is CVE-2003-1316?

The vulnerability in mod.php of eNdonesia 8.2 enables remote attackers to exploit the 'lng' parameter. By injecting a quote character, an attacker can trigger the application to reveal sensitive information, specifically the file path in the response error messages. This unintended disclosure of application paths can lead to further attacks on the system, as it provides attackers with critical insights into the application's structure and file locations.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.