积极预防 及时发现
快速响应 力保恢复
gtDig 3.2 beta、3.1.5以及早期版本中的htsearch程序允许远程攻击者通过使用配...
发布时间:2001-08-31 信息来源:管理员

CNCVE编号:CNCVE-20001191 CVE编号:CAN-2000-1191 安全级别:中 漏洞中文描述: gtDig 3.2 beta、3.1.5以及早期版本中的htsearch程序允许远程攻击者通过使用配置参数请求不存在的配置文件,这个请求产生的错误信息里包含完全路径,从而使攻击者确定服务器的物理路径。 漏洞英文描述: htsearch program in htDig 3.2 beta, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path. 漏洞参考: Reference: MISC:http://www.securiteam.com/exploits/htDig_reveals_web_server_configuration_paths.html 系统类型:其他 漏洞类型:异常处理错误