Joe Testa hellbent 01 allows remote attackers to determine the full path of the web root directory via a GET request with a relative path that includes the root's parent, which generates a 403 error message if the parent is incorrect, but a normal response if the parent is correct.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/3908 | patch vdb entry broken link third party advisory |
http://archives.neohapsis.com/archives/bugtraq/2002-01/0228.html | patch mailing list exploit vendor advisory broken link |
http://www.iss.net/security_center/static/7930.php | patch broken link vdb entry |