The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Http_server |
Apache |
1.3.12 |
1.3.12 |
References