[42275] in bugtraq
Re: Fullpath disclosure in roundcube webmail
daemon@ATHENA.MIT.EDU (roundcube@gmail.com)
Tue Jan 17 17:14:28 2006
Date: 17 Jan 2006 11:53:10 -0000
Message-ID: <20060117115310.11957.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: roundcube@gmail.com
To: bugtraq@securityfocus.com
Since Roundcube is only available in Alpha version, it's pre-configured with a high verbose level. It allows you to configure wether erros should be displayed or just be logged into a file:
$rcmail_config['debug_level'] = 1;
Also the reported error is a custom message that RoundCube produces while checking the GET parameters and not a PHP generated include failure or whatever.
Regards,
Thomas