Vulnerabilities > CVE-2006-4907 - Information Disclosure vulnerability in Ohio State University OSU Httpd 3.10A/3.11Alpha

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
ohio-state-university

Summary

OSU 3.11alpha and 3.10a allows remote attackers to obtain sensitive information via a URL to a non-existent file, which displays the web root path in the resulting error message.

Vulnerable Configurations

Part Description Count
Application
Ohio_State_University
2