[30169] in bugtraq

home help back first fref pref prev next nref lref last post

Path Disclosure in Turba of Horde

daemon@ATHENA.MIT.EDU (Lorenzo Manuel Hernandez Garcia-Hi)
Sat May 17 14:10:50 2003

Date: 17 May 2003 13:18:59 -0000
Message-ID: <20030517131859.19724.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: Lorenzo Manuel Hernandez Garcia-Hierro <security@lorenzohgh.com>
To: bugtraq@securityfocus.com




There is a path disclosure in status.php of Turba module at Horde 2.1,
you get this:

Fatal error: Call to a member function on a non-object 
in /opt/local/apache/htdocs/horde/turba/status.php on line 12

NOTE: i observed that this only occur in Turba....

home help back first fref pref prev next nref lref last post