PT-2000-1791 · Suse+1 · Suse Linux+1
Published
2000-11-14
·
Updated
2017-10-10
·
CVE-2000-0868
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache version 1.3.12
Description
The default configuration of Apache in SuSE Linux allows remote attackers to read source code for CGI scripts by modifying the requested URL. Specifically, replacing the
/cgi-bin/ in the URL with /cgi-bin-sdb/ enables this unauthorized access.Recommendations
For Apache version 1.3.12, consider reconfiguring the server to prevent information disclosure by restricting access to CGI scripts and modifying the default URL handling to prevent source code exposure. As a temporary workaround, restrict access to the
/cgi-bin-sdb/ endpoint to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache
Suse Linux