PT-2002-2450 · Asksam · Asksam Web Publisher

Publicado

2002-12-31

·

Atualizado

2017-07-11

·

CVE-2002-1728

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions askSam Web Publisher versions 1.0 through 4.0
Description The issue allows remote attackers to determine the full path to the web root directory. This is achieved by requesting a file that does not exist, which generates an error message revealing the full path.
Recommendations For askSam Web Publisher versions 1.0 through 4.0, consider restricting access to error messages that may reveal sensitive information about the web root directory until a fix is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1728

Produtos afetados

Asksam Web Publisher