CVE Vulnerabilities

CVE-2001-0947

Published: Dec 04, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path.

Affected Software

NameVendorStart VersionEnd Version
Enterprise_validation_authorityValicert3.3 (including)3.3 (including)
Enterprise_validation_authorityValicert3.4 (including)3.4 (including)
Enterprise_validation_authorityValicert3.5 (including)3.5 (including)
Enterprise_validation_authorityValicert3.6 (including)3.6 (including)
Enterprise_validation_authorityValicert3.7 (including)3.7 (including)
Enterprise_validation_authorityValicert3.8 (including)3.8 (including)
Enterprise_validation_authorityValicert3.9 (including)3.9 (including)
Enterprise_validation_authorityValicert4.0 (including)4.0 (including)
Enterprise_validation_authorityValicert4.1 (including)4.1 (including)
Enterprise_validation_authorityValicert4.2 (including)4.2 (including)
Enterprise_validation_authorityValicert4.2.1 (including)4.2.1 (including)

References