Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ValiCert Enterprise Validation Authority 物理路径泄露漏洞
Vulnerability Description
CVE(CAN) ID: CAN-2001-0947 The ValiCert Validation Authority提供了综合,可靠和可升级的数字证书验证体 系,可以实时支持任何证书授权机构的证书。 其中的CGI程序"forms.exe"存在一个安全问题,可能导致ValiCert物理路径泄露。 恶意用户通过发送一个HTTP请求,要求增加一种自定义的扩展名,如果该扩展名类型不 存在时,软件将返回错误信息,其中就包含了ValiCert的物理路径。
CVSS Information
N/A
Vulnerability Type
N/A