Mozilla Bonsai 1.3 - Full Path Disclosure

Author: Stan Bubrouski
type: webapps
platform: cgi
port: 
date_added: 2002-08-20  
date_updated: 2012-10-04  
verified: 1  
codes: CVE-2003-0153;OSVDB-5463;OSVDB-5462;OSVDB-5459  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 21730.txt  
source: https://www.securityfocus.com/bid/5517/info

A path disclosure vulnerability has been reported in Mozilla Bonsai.

An attacker can exploit this vulnerability by making a malformed request to Bonsai. This causes Bonsai to return an error page to the requesting user. This error page will contain the absolute path information about the requested file.

/bonsai/cvsview2.cgi
/bonsai/multidiff.cgi