Apache Server Address Disclosure...

- AV AC AU C I A
发布: 2001-08-09
修订: 2025-04-13

A vulnerability has been discovered in Apache web server that may result in the disclosure of the server's address. The problem occurs when a HTTP request containing the URI of a directory is submitted to the server. If the URI does not contain a trailing '/' character, the server returns a 3xx redirection error code indicating that further action must be taken in order to fulfill the request. When this occurs, a 'Location' response-header containing the address of the server is returned as part of the response. In a situation where the request is redirected to the server behind a firewall, this could lead to the disclosure of the server's internal network address.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息