Re: [ARL02-A07] ARSC Really Simple Chat System Information Path Disclosure Vulnerability

From: Manuel Kiessling (manuelat_private)
Date: Tue Mar 19 2002 - 00:16:49 PST

  • Next message: Ofir Arkin: "Identifying Kernel 2.4.x based Linux machines using UDP"

    Hello,
    
    Ahmet Sabri ALPER wrote:
    > 
    > A vulnerability exists in ARSC Really Simple Chat, 
    > which could allow any remote user to view the full 
    > path to the web root.
    The fixed version is now available:
    
    Via anonymous FTP:
    ftp://manuel.kiessling.net/pub/arsc/arsc1.0.1p1.tar.gz
    ftp://manuel.kiessling.net/pub/arsc/arsc1.0.1p1.zip
    
    Via HTTP:
    http://manuel.kiessling.net/projects/software/arsc/download/arsc1.0.1p1.tar.gz
    http://manuel.kiessling.net/projects/software/arsc/download/arsc1.0.1p1.zip
    
     From Sourceforge via HTTP:
    http://prdownloads.sourceforge.net/arsc/arsc1.0.1p1.tar.gz
    http://prdownloads.sourceforge.net/arsc/arsc1.0.1p1.zip
    
    --
      Manuel Kiessling
    



    This archive was generated by hypermail 2b30 : Tue Mar 19 2002 - 08:20:26 PST