Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/6093 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2001-02/0216.html | vendor advisory mailing list exploit |
http://www.securityfocus.com/bid/2374 | vendor advisory vdb entry exploit |