[] NeoSense

Oracle Reports Server 6.0.8/9.0.2 - Information Disclosure

Author: skp
type: remote
platform: multiple
port: 
date_added: 2002-07-18 
date_updated: 2012-10-01 
verified: 1 
codes: CVE-2002-1089;OSVDB-6695 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/5262/info

A problem with Reports Server could make it possible to gain sensitive information from the server.

Under some circumstances, Reports Server may yield sensitive information to unauthenticated remote users. This information may include the system path, software installed on the vulnerable system, and other information that may be used as points of entry.

http://some.site.com/cgi-bin/rwcgi60
http://some.site.com/cgi-bin/rwcgi60/showenv