COMMAND

    HSWeb Webserver

SYSTEMS AFFECTED

    HSWeb Webserver 2.0

PROBLEM

    Joe  Testa  found  following.   Any  remote  user can discover the
    physical path of the web root if directory browsing is enabled.

    If directory browsing is enabled, then going to the following URL:

        http://localhost/cgi/

    will cause HSWeb to respond with:

        Directory listing of d:\hs\WWWRoot\cgi\

        Type   File Name          Size  Last Modified

        [DIR]  Parent Directory   -     Sun. 28 Jan 2001 10:38:08 GMT

SOLUTION

    Turn off directory browsing.