Debian Linux httpd Vulnerability

The Debian GNU/Linux 2.1 apache package by default allows anyone to view /usr/doc via the web, remotely. This is because srm.conf is preconfigured with the line:

Alias /doc/ /usr/doc/

Boa is also preconfigured this way.


 

Privacy Statement
Copyright 2010, SecurityFocus