Apache HTTP Server, when running on Linux with a document root on a Windows share mounted using smbfs, allows remote attackers to obtain unprocessed content such as source files for .php programs via a trailing "\" (backslash), which is not handled by the intended AddType directive.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/485316/100/0/threaded | mailing list |
http://securityreason.com/securityalert/3479 | third party advisory |
http://www.securityfocus.com/bid/26939 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39158 | vdb entry |