PT-2002-1193 · Cacheflow · Cacheflow Cacheos

Publicado

2002-03-25

·

Atualizado

2016-10-18

·

CVE-2002-0107

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions CacheFlow CacheOS versions 4.0.13 and earlier
Description The web administration interface in CacheFlow CacheOS allows remote attackers to obtain sensitive information via a series of GET requests that do not end with 'HTTP/1.0' or another version string. This causes the information to be leaked in the error message.
Recommendations For CacheFlow CacheOS versions 4.0.13 and earlier, consider restricting access to the web administration interface until a fix is available. As a temporary workaround, ensure that all GET requests to the interface include a valid HTTP version string to prevent information leakage.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0107

Produtos afetados

Cacheflow Cacheos