10 lines
No EOL
561 B
Text
10 lines
No EOL
561 B
Text
source: https://www.securityfocus.com/bid/7207/info
|
|
|
|
An information disclosure vulnerability has been reported for Sambar Server. The vulnerability exists in some files existing in Sambar Server's cgi-bin directory.
|
|
|
|
An attacker can exploit this vulnerability by making a request for these files. This will result in Sambar Server returning potentially sensitive information.
|
|
|
|
An attacker can use the information obtained in this manner to launch further attacks against a vulnerable host.
|
|
|
|
http://[target]/cgi-bin/environ.pl
|
|
http://[target]/cgi-bin/testcgi.exe |