漏洞信息详情
Windows Apache 2 OPTIONS请求路径泄露漏洞
- CNNVD编号:CNNVD-200205-057
- 危害等级: 中危
- CVE编号:
CVE-2002-0240
- 漏洞类型:
配置错误
- 发布时间:
2002-05-29
- 威胁类型:
远程
- 更新时间:
2006-04-07
- 厂 商:
apache - 漏洞来源:
.’);”>Discovered by “Pau… -
漏洞简介
PHP在带Apache安装并将index.php的search像默认web页面一样进行配置时存在漏洞。远程攻击者可以借助HTTP OPTIONS方法获取服务器全路径名称,该漏洞可能在产生的错误消息中泄露路径名称。
漏洞公告
It may be possible to surpress this information through the Apache configuration. This has not been confirmed.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com
参考网址
来源: BID
名称: 4057
链接:http://www.securityfocus.com/bid/4057
来源: XF
名称: apache-php-options-information(8119)
链接:http://www.iss.net/security_center/static/8119.php
来源: BUGTRAQ
名称: 20020207 PHP Advisory #2
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=101311746611160&w=2