积极预防 及时发现
快速响应 力保恢复
HSWeb 2.0 HTTP 服务器允许远程攻击者通过对/cgi/目录的一个请求来获得服务器的物理路...
发布时间:2001-05-03 信息来源:管理员

CNCVE编号:CNCVE-20010200 CVE编号:CAN-2001-0200 安全级别:中 漏洞中文描述: HSWeb 2.0 HTTP 服务器允许远程攻击者通过对/cgi/目录的一个请求来获得服务器的物理路径,那么当目录浏览被激活时,这会列出路径。 漏洞英文描述: HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path if directory browsing is enabled. 漏洞参考: BID:2336 BUGTRAQ:20010204 Web root exposure in HSWeb Webserver 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:输入有效性检查错误