Record summary

CVE-2003-1089 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names, which reveals the path in a PHP error message.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBPHPOutsourcing Zorum 3.4 - Full Path DisclosureExploitDB exploitby Zone-h Security TeamNot analyzed1 file
ExploitDB

PoC details

References

5