Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path in an error message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sage | Sage | 1.0_beta_3 (including) | 1.0_beta_3 (including) |