Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names.
The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2001-06/0328.html | mailing list broken link patch vendor advisory |
http://www.securityfocus.com/bid/2926 | patch vendor advisory exploit vdb entry third party advisory broken link |