vendor:
WebWeaver
by:
SecurityFocus
3.3
CVSS
MEDIUM
Path Disclosure
200
CWE
Product Name: WebWeaver
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: a:blaine_southam:webweaver
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
BRS WebWeaver FTP Path Disclosure Vulnerability
By submitting the FTP command CD argumented by an asterisk character, the attacker can cause an error message to be generated by WebWeaver which includes the path for the ftp root.
Mitigation:
Restrict access to the FTP service to trusted hosts and networks.