IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a request is made for a non-existent Java Server Page (JSP).
Link | Tags |
---|---|
http://www.iss.net/security_center/static/10628.php | vdb entry |
http://www.securityfocus.com/bid/6181 | vdb entry |
http://marc.info/?l=bugtraq&m=103726020802411&w=2 | mailing list |