Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM Net.Data远程路径泄露漏洞
Vulnerability Description
IBM Net.Data是脚本语言,用来构建Web应用程序。它支持范围广泛的语言环境,并且和大多数熟知的数据库相兼容。 Net.Data实现上存在一个问题,远程攻击者可能利用此漏洞泄露收集到服务器相关的有用信息。 通过使用CGI应用程序的方法提交一个特殊构造的URL,使得它包含一个无效的请求和已知数据库,将泄露服务器文件系统的物理路径。成功地利用这个漏洞有助于进一步进行攻击。
CVSS Information
N/A
Vulnerability Type
N/A