PT-2002-2360 · Apache+1 · Apache+1
Publicado
2002-12-31
·
Atualizado
2017-07-11
·
CVE-2002-1635
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle 9i Application Server (9iAS)
Description
The issue arises from the Apache configuration file (httpd.conf) in Oracle 9i Application Server (9iAS), where a Location alias is used for the /perl directory instead of a ScriptAlias. This configuration allows remote attackers to read the source code of arbitrary CGI files by accessing a URL that contains the /perl directory instead of /cgi-bin.
Recommendations
For Oracle 9i Application Server (9iAS), consider modifying the Apache configuration file (httpd.conf) to use a ScriptAlias for the /perl directory instead of a Location alias to prevent remote attackers from reading the source code of arbitrary CGI files.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache
Oracle 9I Application Server