Apache 2.2.2 - CGI Script Source Code Information Disclosure

EDB-ID:

28365


Author:

Susam Pal

Type:

remote


Platform:

Multiple

Date:

2006-08-09


source: https://www.securityfocus.com/bid/19447/info

Apache is prone to an information-disclosure vulnerability because it fails to properly handle exceptional conditions.

An attacker can exploit this issue to retrieve script source code. Information obtained may aid in further attacks.

Versions 2.2.2 for Microsoft Windows is vulnerable to this issue; other versions may also be affected.

http://www.example.com/CGI-BIN/foo