CVE
- Id
- 3124
- CVE No.
- CVE-2001-0303
- Status
- Candidate
- Description
- tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to determine the physical path of the server via a URL that requests a non-existent file.
- Phase
- Proposed (20010404)
- Votes
- ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Bishop
- Comments
- Frech> XF:pi3web-reveal-path(6114) | Christey> This issue was rediscovered a year later, in version 2.0.0. | Since it"s a default configuration problem, it is likely that | the vendor did not fix it. | BUGTRAQ:20020310 Pi3Web/2.0.0 File-Disclosure/Path Disclosure vuln | URL:http://online.securityfocus.com/archive/1/260734 | BID:4261 | XF:pi3web-error-disclosure(8428)