Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.osvdb.org/34154 | vdb entry |
http://www.securityfocus.com/bid/23687 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34167 | vdb entry |
http://attrition.org/pipermail/vim/2007-April/001562.html | mailing list |