PT-2002-2610 · Commonname · Commonname Toolbar

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-1888

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions CommonName Toolbar version 3.5.2.0
Description The issue concerns the CommonName Toolbar sending unqualified domain name requests to the CommonName organization and possibly other web servers for name resolution. This allows those organizations to obtain internal server names.
Recommendations For CommonName Toolbar version 3.5.2.0, consider restricting access to internal server names to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1888

Produtos afetados

Commonname Toolbar