Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=100749428517090&w=2 | |
http://www.securityfocus.com/bid/3615 | Patch Vendor Advisory |
http://www.valicert.com/support/security_advisory_eva.html | Vendor Advisory URL Repurposed |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7649 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2002-02-02T05:00:00
Updated: 2017-12-18T21:57:01
Reserved: 2002-01-31T00:00:00
Link: CVE-2001-0947
JSON object: View
NVD Information
Status : Modified
Published: 2001-12-04T05:00:00.000
Modified: 2024-02-14T01:17:43.863
Link: CVE-2001-0947
JSON object: View
Redhat Information
No data.
CWE