OSU 3.11alpha and 3.10a allows remote attackers to obtain sensitive information via a URL to a non-existent file, which displays the web root path in the resulting error message.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Osu_httpd | Ohio_state_university | 3.10a (including) | 3.10a (including) |
| Osu_httpd | Ohio_state_university | 3.11alpha (including) | 3.11alpha (including) |