PT-2000-1791 · Suse+1 · Suse Linux+1
Publicado
2000-11-14
·
Atualizado
2017-10-10
·
CVE-2000-0868
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache version 1.3.12
Description
The default configuration of Apache in SuSE Linux allows remote attackers to read source code for CGI scripts by modifying the requested URL. Specifically, replacing the
/cgi-bin/ in the URL with /cgi-bin-sdb/ enables this unauthorized access.Recommendations
For Apache version 1.3.12, consider reconfiguring the server to prevent information disclosure by restricting access to CGI scripts and modifying the default URL handling to prevent source code exposure. As a temporary workaround, restrict access to the
/cgi-bin-sdb/ endpoint to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache
Suse Linux