Security Advisory

CVE-2002-0245

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2002-05-03 04:00:00
Last updated 2024-08-08 02:42:28
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Lotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexistent file with a .pl (Perl) extension, which leaks the pathname in the error message, or (2) make any request that causes an HTTP 500 error, which leaks the server's version name in the HTTP error message.