vendor:
eZ Publish
by:
SecurityFocus
5
CVSS
MEDIUM
Path Disclosure
200
CWE
Product Name: eZ Publish
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Path Disclosure Vulnerabilities in eZ Publish
Several path disclosure vulnerabilities have been reported for eZ Publish. An attacker can exploit this vulnerability by making a HTTP request for any of the affected pages. This may result in a condition where path information is returned to the attacker.
Mitigation:
Ensure that the web server is configured to not return directory paths in response to requests.