Oracle Application Server 9i 'httpd.conf' Information Disclosure Vulnerability
BID:49633
Info
Oracle Application Server 9i 'httpd.conf' Information Disclosure Vulnerability
| Bugtraq ID: | 49633 |
| Class: | Design Error |
| CVE: |
CVE-2002-1635 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2002 12:00AM |
| Updated: | Feb 26 2002 12:00AM |
| Credit: | David Litchfield |
| Vulnerable: |
Oracle Oracle9i Application Server |
| Not Vulnerable: | |
Discussion
Oracle Application Server 9i 'httpd.conf' Information Disclosure Vulnerability
Oracle Application Server 9i is prone to a remote information-disclosure vulnerability.
Remote attackers can exploit this issue to obtain sensitive information.
Oracle Application Server 9i is prone to a remote information-disclosure vulnerability.
Remote attackers can exploit this issue to obtain sensitive information.
Exploit / POC
Oracle Application Server 9i 'httpd.conf' Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle Application Server 9i 'httpd.conf' Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Oracle Application Server 9i 'httpd.conf' Information Disclosure Vulnerability
References:
References:
- Oracle Homepage (Oracle)
- Oracle 9iAS allows access to CGI script source code within CGI-BIN directory (David Litchfield)
- Oracle9i Application Server '/perl' alias could allow an attacker to view CGI so (David Litchfield)