Description
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
Affected products
- apache / http_server1.3.12 – 1.3.12
- SUSE / suse_linux6.3 – 6.3
- SUSE / suse_linux6.4 – 6.4