Full directory path listing
P
Paragon Initiative Enterprises
Submitted None
Actions:
Reported by
test_this
Vulnerability Details
Technical details and impact analysis
STEP:
====================
1. goto https://bridge.cspr.ng/login and enter your username,password
2. click "LogIn" and intercept the request
3. change the value in cookie header and add '(single quote) in PHPSESSID field
eg: PHPSESSID=kn7e21dpp2ocai2ckn1v147qev'
4. Forward the packet and see full path is disclose
{F186342}
Report Details
Additional information and metadata
State
Closed
Substate
Spam
Submitted
Weakness
Information Exposure Through Directory Listing