The Gossamer Threads DBMan db.cgi CGI script allows remote attackers to view environmental variables and setup information by referencing a non-existing database in the db parameter.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/1178 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2000-05/0067.html | mailing list |
http://www.perfectotech.com/blackwatchlabs/vul5_05.html | url repurposed |