PT-2001-1966 · Igss · Air Messenger Lan Server
Publicado
2001-10-12
·
Atualizado
2008-09-05
·
CVE-2001-0788
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Air Messenger LAN Server version 3.4.2
Description
The issue allows remote attackers to obtain the absolute path for the server directory. This is achieved by viewing the Location header.
Recommendations
For Air Messenger LAN Server version 3.4.2, consider restricting access to sensitive server directories until a patch is available. As a temporary workaround, modify server configurations to prevent the disclosure of the server directory path in the Location header.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Air Messenger Lan Server