Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.11071
Category:Web application abuses
Title:ASP/PHP '%20' Source Code Disclosure Vulnerability - Active Check
Summary:Multiple products are prone to an information disclosure; vulnerability.
Description:Summary:
Multiple products are prone to an information disclosure
vulnerability.

Vulnerability Insight:
It is possible to get the source code of the remote
ASP/PHP scripts by appending %20 at the end of the request (like GET /default.asp%20).

Vulnerability Impact:
ASP/PHP source code could usually contain sensitive
information.

Affected Software/OS:
The following products are known to be affected:

- vWebServer 1.2

- SHTTPD 1.38

Other products / versions might be affected as well.

Solution:
Install all the latest security patches for the affected
product or contact the vendor for a solution.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2001-1248
BugTraq ID: 2975
http://www.securityfocus.com/bid/2975
Bugtraq: 20010629 4 New vulns. vWebServer and SmallHTTP (Google Search)
http://online.securityfocus.com/archive/1/194418
http://www.iss.net/security_center/static/6769.php
Common Vulnerability Exposure (CVE) ID: CVE-2007-3407
BugTraq ID: 24618
http://www.securityfocus.com/bid/24618
Bugtraq: 20070623 SHTTPD V1.38 server source code disclosure (Google Search)
http://www.securityfocus.com/archive/1/472190/100/0/threaded
http://osvdb.org/37732
http://secunia.com/advisories/25809
http://securityreason.com/securityalert/2832
XForce ISS Database: simplehttpd-extension-source-code-disclosure(35038)
https://exchange.xforce.ibmcloud.com/vulnerabilities/35038
CopyrightCopyright (C) 2002 Michel Arboi

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.