sbox version 1.04, the CGI wrapper that allows for safer execution of scripts, has a path disclosure vulnerability.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/31713/sbox-adv.txt
Source: https://packetstormsecurity.com/files/31713/sbox-adv.txt.html