The Gossamer Threads DBMan db.cgi CGI script allows remote attackers to view environmental variables and setup information by referencing a non-existing database in the db parameter.Referenceshttp://www.securityfocus.com/bid/1178http://archives.neohapsis.com/archives/bugtraq/2000-05/0067.htmlhttp://www.perfectotech.com/blackwatchlabs/vul5_05.html