PT-2002-2401 · Unknown · Mrtgconfig

Publicado

2002-12-31

·

Atualizado

2017-07-11

·

CVE-2002-1677

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions mrtgconfig versions 1.1p15
Description The issue allows remote attackers to determine the physical path to the web root directory. This is achieved by sending a request with an invalid cfg parameter to the 14all.cgi script, which generates an error message that reveals the path.
Recommendations For version 1.1p15, consider restricting access to the 14all.cgi script until a patch is available. As a temporary workaround, avoid using the cfg parameter in the affected script to minimize the risk of path disclosure.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1677

Produtos afetados

Mrtgconfig