Security Advisory
CVE-2001-0947
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path.