askSam Web Publisher 1.0 and 4.0 allows remote attackers to determine the full path to the web root directory via a request for a file that does not exist, which generates an error message that reveals the full path.Referenceshttp://online.securityfocus.com/archive/82/270970http://www.securityfocus.com/bid/4670http://www.ifrance.com/kitetoua/tuto/5holes4.txthttps://exchange.xforce.ibmcloud.com/vulnerabilities/9004