[] NeoSense

WebTrends Enterprise Reporting Server 3.1 c/3.5 - Source Code Disclosure

Author: Auriemma Luigi
type: remote
platform: cgi
port: 
date_added: 2001-06-03 
date_updated: 2012-08-29 
verified: 1 
codes: CVE-2001-0693;OSVDB-6157 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/2812/info

WebTrends Live is a web-based reporting service which provides interactive tracking of usage statistics and E-commerce revenue.

It is possible to view the source code of arbitrary scripts on the WebTrends Live webserver. This is accomplished by crafting a URL with an encoded space after the filename of the script.

http://host/remote_login.pl%20