Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte (%00) to a URL or (2) an invalid LANGUAGE parameter to web.tmpl, which reveals the full installation path in an error message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gattaca_server_2003 | Geeos_team | 1.1.10.0 (including) | 1.1.10.0 (including) |