PT-2001-2172 · Xcache · Xcache

Publicado

2001-09-21

·

Atualizado

2017-12-19

·

CVE-2001-1023

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xcache version 2.1
Description The issue allows remote attackers to determine the absolute path of web server documents. This is achieved by requesting a URL that is not cached, which returns the full pathname in the Content-PageName header.
Recommendations For Xcache version 2.1, update to a version where this issue is fixed, as the current version allows attackers to obtain sensitive information about the web server's document path.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-1023

Produtos afetados

Xcache