Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email email@example.com
Date: Tue Apr 17 2001 - 09:50:40 CDT
Lotus Domino is a webserver. It has a simple
physical path revealing problem.
/-|=[who is vulnerable]=|-\
The above are versions I am sure of, but I assume
most 4.6.x and lower version are vulnerable.
for some reason Lotus-Domino Release-5.0.2
sometimes showed the physical path and sometimes it
did not. I do not know the reason for this.
NOT vulnerable is
This works on both NT and non-NT computers.
To test this vulnerability, try the following.
This should give you a error with a physical path.
Seeing as this can be fixed by upgrading I did not
Free, encrypted, secure Web-based email at www.hushmail.com