Aiglon Web Server Installation Path Information Disclosure Weakness
BID:7867
Info
Aiglon Web Server Installation Path Information Disclosure Weakness
| Bugtraq ID: | 7867 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2003 12:00AM |
| Updated: | Jun 10 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Ziv Kamir <[email protected]>. |
| Vulnerable: |
Denis Verreault Aiglon web server 2.0 |
| Not Vulnerable: | |
Discussion
Aiglon Web Server Installation Path Information Disclosure Weakness
A weakness has been discovered in Aiglon Web Server, which may provide for the disclosure of sensitive information to remote attackers.
It has been reported that a remote attacker may cause the web server to disclose installation path details by making a malformed HTTP request. The remote attacker may potentially use the disclosed information to aid in further "intelligent" attacks against the host running the affected software.
A weakness has been discovered in Aiglon Web Server, which may provide for the disclosure of sensitive information to remote attackers.
It has been reported that a remote attacker may cause the web server to disclose installation path details by making a malformed HTTP request. The remote attacker may potentially use the disclosed information to aid in further "intelligent" attacks against the host running the affected software.
Exploit / POC
Aiglon Web Server Installation Path Information Disclosure Weakness
The following proof of concept exploit has been provided:
http://www.example.com/index.html*
The following proof of concept exploit has been provided:
http://www.example.com/index.html*
Solution / Fix
Aiglon Web Server Installation Path Information Disclosure Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.