Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache httpd 信息泄露漏洞
Vulnerability Description
Apache httpd是美国阿帕奇(Apache)基金会的一款专为现代操作系统开发和维护的开源HTTP服务器。 Apache httpd 1.5及以前版本和Apache Web Server 1.0以前的版本的ScriptAlias功能存在信息泄露漏洞。如果ScriptAlias目录定义在DocumentRoot下,远程攻击者可以浏览Web服务器上CGI程序的源码。如果索引功能打开的话,在URL里使用多个斜杠还可以列出CGI-BIN目录的列表。远程攻击者可以利用这个漏洞查看脚本的代码,进一步审计这些脚本
CVSS Information
N/A
Vulnerability Type
N/A