Apache 2.0 - Full Path Disclosure

Related Vulnerabilities: CVE-2002-0654  
Publish Date: 16 Aug 2002
                							

                source: http://www.securityfocus.com/bid/5485/info

A path disclosure vulnerability has been reported in Apache 2.0.x.

It is possible to reproduce this condition on vulnerable systems by making a request for certain types of files (such as error documents) that have been mapped by the server by type but fail to be served due to failure of MIME negotiation.

http://target/error/HTTP_NOT_FOUND.html.var