ActiveState ActivePerl Path Revealing Vulnerability
BID:3770
Info
ActiveState ActivePerl Path Revealing Vulnerability
| Bugtraq ID: | 3770 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2001 12:00AM |
| Updated: | Dec 29 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by antoan miroslavov <[email protected]>. |
| Vulnerable: |
Activestate ActivePerl 5.6.1 |
| Not Vulnerable: | |
Discussion
ActiveState ActivePerl Path Revealing Vulnerability
ActivePerl is an implementation of the Perl scripting language for Microsoft Windows systems developed by ActiveState.
A vulnerability exists that could allow a malicious user to view the full path to the web root by sending the server a request for a non-existant .pl file.
This request could cause the server to send a message revealing the web root path information.
ActivePerl is an implementation of the Perl scripting language for Microsoft Windows systems developed by ActiveState.
A vulnerability exists that could allow a malicious user to view the full path to the web root by sending the server a request for a non-existant .pl file.
This request could cause the server to send a message revealing the web root path information.
Exploit / POC
ActiveState ActivePerl Path Revealing Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
ActiveState ActivePerl Path Revealing Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.