bugzilla.mozilla.orgConfirmation
http://bugzilla.mozilla.org/show_bug.cgi?id=187230 CVE-2003-0153
Mozilla Bonsai 1.3 - Full Path Disclosure
Record summary
CVE-2003-0153 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
bonsai Mozilla CVS query tool leaks the absolute pathname of the tool in certain error messages generated by (1) cvslog.cgi, (2) cvsview2.cgi, or (3) multidiff.cgi.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMozilla Bonsai 1.3 - Full Path DisclosureExploitDB exploitby Stan BubrouskiNot analyzed1 file
References
620020819 Advisory: Bonsai XSS and Physical Path Revealing Vulnerabilitiesmailing list
http://marc.info/?l=bugtraq&m=102980129101054&w=2 DSA-265Vendor advisory
http://www.debian.org/security/2003/dsa-265 5517vdb entry
http://www.securityfocus.com/bid/5517 bonsai-path-disclosure(9921)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/9921 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0153