SuSE Installed Package Disclosure...

- AV AC AU C I A
发布: 2000-09-21
修订: 2025-04-13

By submitting a specific url to the web server ("http://hosts.any/doc/packages/") , any user from any host may obtain a list of packages installed on a S.u.S.E 6.3 or 6.4 system. This problem is due to a configuration in the Apache httpd.conf supplied with S.u.S.E that permits anyone to request documents from this webroot subdirectory. The end result is that attackers will know what packages the victim has installed, which can assist in executing more complicated attacks.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息