Vulnerability Name: | CVE-2002-1635 (CCN-10716) | ||||||||
Assigned: | 2002-02-26 | ||||||||
Published: | 2002-02-26 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | The Apache configuration file (httpd.conf) in Oracle 9i Application Server (9iAS) uses a Location alias for /perl directory instead of a ScriptAlias, which allows remote attackers to read the source code of arbitrary CGI files via a URL containing the /perl directory instead of /cgi-bin. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2002-1635 Source: CCN Type: US-CERT VU#936507 Oracle 9iAS allows access to CGI script source code within CGI-BIN directory Source: CERT-VN Type: US Government Resource VU#936507 Source: MISC Type: UNKNOWN http://www.nextgenss.com/papers/hpoas.pdf Source: CCN Type: OSVDB ID: 18220 Oracle 9iAS httpd.confg /perl Location Alias Arbitrary CGI File Script Disclosure Source: XF Type: UNKNOWN oracle-perl-cgi-source(10716) Source: XF Type: UNKNOWN oracle-perl-cgi-source(10716) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |