PT-2000-1576 · Webactive · Webactive Http Server
Publicado
2000-07-12
·
Atualizado
2017-10-10
·
CVE-2000-0642
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WebActive HTTP Server version 1.00
Description
The default configuration of the software stores the web access log active.log in the document root. This allows remote attackers to view the logs by directly requesting the page.
Recommendations
For WebActive HTTP Server version 1.00, consider moving the active.log file to a location outside of the document root to prevent unauthorized access. As a temporary workaround, restrict access to the active.log file until a more permanent solution is implemented.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Webactive Http Server