ICQ99 ICQ web server build 1701 with "Active Homepage" enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists ("404 Forbidden") versus when a file does not exist ("404 not found").
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/13508 | mailing list patch vendor advisory |
http://www.securityfocus.com/bid/246 | vdb entry |