COMMAND
HSWeb Webserver
SYSTEMS AFFECTED
HSWeb Webserver 2.0
PROBLEM
Joe Testa found following. Any remote user can discover the
physical path of the web root if directory browsing is enabled.
If directory browsing is enabled, then going to the following URL:
http://localhost/cgi/
will cause HSWeb to respond with:
Directory listing of d:\hs\WWWRoot\cgi\
Type File Name Size Last Modified
[DIR] Parent Directory - Sun. 28 Jan 2001 10:38:08 GMT
SOLUTION
Turn off directory browsing.