Vulnerabilities > CVE-2001-0200 - Path Disclosure vulnerability in Heat-On Software Hsweb 2.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path if directory browsing is enabled.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Heat-On HSWeb Web Server 2.0 Path Disclosure Vulnerability. CVE-2001-0200. Remote exploit for cgi platform |
id | EDB-ID:20609 |
last seen | 2016-02-02 |
modified | 2001-02-04 |
published | 2001-02-04 |
reporter | Joe Testa |
source | https://www.exploit-db.com/download/20609/ |
title | Heat-On HSWeb Web Server 2.0 Path Disclosure Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | HSWEB_LOCATION.NASL |
description | It is possible to request the physical location of the remote web root by requesting the folder '/cgi'. An attacker can exploit this flaw to gain more knowledge about this host. This plugin has been deprecated. Webmirror3 (plugin ID 10662) will identify a browsable directory. |
last seen | 2018-06-14 |
modified | 2018-06-13 |
plugin id | 10606 |
published | 2001-02-08 |
reporter | Tenable |
source | https://www.tenable.com/plugins/index.php?view=single&id=10606 |
title | HSWeb HTTP Server /cgi Directory Request Path Disclosure (deprecated) |
code |
|