Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 up to and including 4.2.1 allows remote malicious users to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
valicert enterprise validation authority 3.3 |
||
valicert enterprise validation authority 4.0 |
||
valicert enterprise validation authority 4.1 |
||
valicert enterprise validation authority 3.4 |
||
valicert enterprise validation authority 3.5 |
||
valicert enterprise validation authority 4.2 |
||
valicert enterprise validation authority 4.2.1 |
||
valicert enterprise validation authority 3.8 |
||
valicert enterprise validation authority 3.9 |
||
valicert enterprise validation authority 3.6 |
||
valicert enterprise validation authority 3.7 |