CVE-2001-0947
N/A
N/A
Summary
Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7649
- http://marc.info/?l=bugtraq&m=100749428517090&w=2
- http://www.valicert.com/support/security_advisory_eva.html
- http://www.securityfocus.com/bid/3615
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7649
- http://marc.info/?l=bugtraq&m=100749428517090&w=2
- http://www.valicert.com/support/security_advisory_eva.html
- http://www.securityfocus.com/bid/3615
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.