Vulnerabilities > CVE-2000-1016 - Unspecified vulnerability in Suse Linux 6.3/6.4

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
suse
nessus
exploit available

Summary

The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows remote attackers to read package documentation and obtain system configuration information via an HTTP request for the /doc/packages URL.

Vulnerable Configurations

Part Description Count
OS
Suse
2

Exploit-Db

descriptionS.u.S.E. Linux 6.3/6.4 Installed Package Disclosure Vulnerability. CVE-2000-1016. Remote exploit for linux platform
idEDB-ID:20236
last seen2016-02-02
modified2000-09-21
published2000-09-21
reportert0maszek
sourcehttps://www.exploit-db.com/download/20236/
titleS.u.S.E. Linux 6.3/6.4 Installed Package Disclosure Vulnerability

Nessus

NASL familyCGI abuses
NASL idDOC_PACKAGE_BROWSEABLE.NASL
descriptionThe /doc/packages directory is browsable. This directory contains the versions of the packages installed on this host. A remote attacker can use this information to mount further attacks. This plugin has been deprecated. Webmirror3 (plugin ID 10662) will identify a browsable directory.
last seen2018-06-14
modified2018-06-13
plugin id10518
published2000-09-25
reporterTenable
sourcehttps://www.tenable.com/plugins/index.php?view=single&id=10518
title/doc/packages Directory Browsable (deprecated)