WebTrends Enterprise Reporting Server 3.1 c/3.5 - Source Code Disclosure
Author: Auriemma Luigi
type: remote
platform: cgi
port:
date_added: 2001-06-03
date_updated: 2012-08-29
verified: 1
codes: CVE-2001-0693;OSVDB-6157
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/2812/info
WebTrends Live is a web-based reporting service which provides interactive tracking of usage statistics and E-commerce revenue.
It is possible to view the source code of arbitrary scripts on the WebTrends Live webserver. This is accomplished by crafting a URL with an encoded space after the filename of the script.
http://host/remote_login.pl%20