Sensitive Configuration Information Disclosure in Xitami 2.5b's Default testcgi.exe Program

Sensitive Configuration Information Disclosure in Xitami 2.5b's Default testcgi.exe Program

CVE-2000-1225 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

Xitami 2.5b installs the testcgi.exe program by default in the cgi-bin directory, which allows remote attackers to gain sensitive configuration information about the web server by accessing the program.

Learn more about our Web App Pen Testing.