This is a writeup detailing two Full Path Disclosure vulnerabilities in PBBoard <= 2.0.2. The vulnerabilities allow attackers to gather the real path of server-side scripts by triggering errors through crafted GET requests.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:PBBoard <= 2.0.2
No auth needed
Prerequisites:Access to the target web application