Full Path disclosure in roundcube webmail v0.1 Author : Ph03n1X date : 17 december 2005 mail : king_purba@yahoo.co.uk vendor : www.roundcube.net security risk : low vendor : already contacted Description: Remote attacker can access the file to display an error report that gave information about installation path. I try this request in my mailbox http://xxxx.com/roundcube/?_auth=3Dcf559dcf52d8801ccd51cd1f3ba3eca08d1b0bce= &_task=3Dma%60il then roundcube shows this warning **PHP Error in /usr/local/apache2/htdocs/roundcube/index.php (301)*:* Invalid request failed/file not found The requested page was not found! Please contact your server-administrator. *Failed request:* http://xxxx.com/roundcube/?_auth=3Dcf559dcf52d8801ccd51cd1f3ba3eca08d1b0bce= &_task=3Dma%60il fix : ?? :) --> edit php.ini to turn off display error display_errors = Off log_errors = On You may see this report in http://www.securityfocus.com/archive/1/419706/30/0/threaded