First published: Tue Nov 14 2000(Updated: )
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache HTTP Server | =1.3.12 | |
SUSE Linux | =6.3 | |
SUSE Linux | =6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0868 has a moderate severity rating as it allows remote attackers to access sensitive source code.
To fix CVE-2000-0868, you should adjust the Apache configuration to disable the exposure of source files.
CVE-2000-0868 affects Apache version 1.3.12 and specific versions of SUSE Linux, including 6.3 and 6.4.
While CVE-2000-0868 is an older vulnerability, it can still pose risks if legacy systems are in use.
CVE-2000-0868 is associated with a path manipulation attack that allows unauthorized access to CGI script source code.