CVE-2004-0665
csFAQ - Information Disclosure via Invalid Database Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-0665. PoCs published by DarkBicho.
AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in csFAQ by manipulating the 'database' parameter to reveal the installation path. The attack leverages improper input validation to disclose sensitive filesystem information.
Description
csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the web server in an error message.
Exploits (1)
This exploit demonstrates an information disclosure vulnerability in csFAQ by manipulating the 'database' parameter to reveal the installation path. The attack leverages improper input validation to disclose sensitive filesystem information.