PT-2001-2172 · Xcache · Xcache
Publicado
2001-09-21
·
Atualizado
2017-12-19
·
CVE-2001-1023
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Xcache version 2.1
Description
The issue allows remote attackers to determine the absolute path of web server documents. This is achieved by requesting a URL that is not cached, which returns the full pathname in the Content-PageName header.
Recommendations
For Xcache version 2.1, update to a version where this issue is fixed, as the current version allows attackers to obtain sensitive information about the web server's document path.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Xcache