[42275] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Fullpath disclosure in roundcube webmail

daemon@ATHENA.MIT.EDU (roundcube@gmail.com)
Tue Jan 17 17:14:28 2006

Date: 17 Jan 2006 11:53:10 -0000
Message-ID: <20060117115310.11957.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: roundcube@gmail.com
To: bugtraq@securityfocus.com

Since Roundcube is only available in Alpha version, it's pre-configured with a high verbose level. It allows you to configure wether erros should be displayed or just be logged into a file:
$rcmail_config['debug_level'] = 1;

Also the reported error is a custom message that RoundCube produces while checking the GET parameters and not a PHP generated include failure or whatever.

Regards,
Thomas

home help back first fref pref prev next nref lref last post