vendor:
Web+
by:
SecurityFocus
6.4
CVSS
MEDIUM
Source Code Disclosure
200
CWE
Product Name: Web+
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Talentsoft Web+ Source Code Disclosure Vulnerability
Talentsoft Web+ is a web application server that can be integrated with various web technologies. Web+ can be used to display the source code of WML files residing on an NTFS parition by appending certain data to the known WML file. This vulnerability is also known to work if the scripts directory is set to the web root which enables the disclosure of other script (eg. ASP files) source code. Successful exploitation of this vulnerability may reveal source code, table names, usernames, passwords, and other forms of confidential data.
Mitigation:
Ensure that the scripts directory is not set to the web root and that the NTFS partition is not accessible from the web.