PT-2002-2360 · Apache+1 · Apache+1

Publicado

2002-12-31

·

Atualizado

2017-07-11

·

CVE-2002-1635

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle 9i Application Server (9iAS)
Description The issue arises from the Apache configuration file (httpd.conf) in Oracle 9i Application Server (9iAS), where a Location alias is used for the /perl directory instead of a ScriptAlias. This configuration allows remote attackers to read the source code of arbitrary CGI files by accessing a URL that contains the /perl directory instead of /cgi-bin.
Recommendations For Oracle 9i Application Server (9iAS), consider modifying the Apache configuration file (httpd.conf) to use a ScriptAlias for the /perl directory instead of a Location alias to prevent remote attackers from reading the source code of arbitrary CGI files.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1635

Produtos afetados

Apache
Oracle 9I Application Server