Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Full Path Discolosure Bug #4841

Closed
anonymous-matomo-user opened this issue Mar 11, 2014 · 1 comment
Closed

Full Path Discolosure Bug #4841

anonymous-matomo-user opened this issue Mar 11, 2014 · 1 comment
Labels
Bug For errors / faults / flaws / inconsistencies etc. Major Indicates the severity or impact or benefit of an issue is much higher than normal but not critical. worksforme The issue cannot be reproduced and things work as intended.

Comments

@anonymous-matomo-user
Copy link

Hello , I found Full Path Discolsure bug on your website ( on your blog )
A malicious attacker could use this bug to know where does his files go when he submit an attack .
Here is the link :
http://crowdfunding.piwik.org/wp-content/plugins/ignitiondeck/templates/admin/_orderView.php

We can see :
/home/crowdfunding/www/crowdfunding.piwik.org

Thanks for answering .
Keywords: bug

@mattab
Copy link
Member

mattab commented Mar 12, 2014

Thanks for the report!

please see our security page: http://piwik.org/security/

Notes: Vulnerabilities such as Path disclosure, Information disclosure, Open Directory Listing, Application Errors on pages, User logins and emails enumeration, do not qualify for the bounty program. Please do not send us emails with these reports.

This issue was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Bug For errors / faults / flaws / inconsistencies etc. Major Indicates the severity or impact or benefit of an issue is much higher than normal but not critical. worksforme The issue cannot be reproduced and things work as intended.
Projects
None yet
Development

No branches or pull requests

2 participants