list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter.Referenceshttp://securitytracker.com/id?1011463http://secunia.com/advisories/12695http://www.securityfocus.com/bid/11283http://marc.info/?l=bugtraq&m=109655691512298&w=2http://lists.grok.org.uk/pipermail/full-disclosure/2004-September/027040.html