PT-2004-1136 · Port80+1 · Servermask+1

Martin Oneal

·

Publicado

2004-08-18

·

Atualizado

2017-07-11

·

CVE-2003-0105

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ServerMask versions 2.2 and earlier
Description The issue concerns the lack of obfuscation for certain HTTP responses, specifically (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could reveal to remote attackers that the web server is an IIS server.
Recommendations For ServerMask versions 2.2 and earlier, consider updating to a version that properly obfuscates these HTTP responses to prevent disclosure of the web server type. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0105

Produtos afetados

Iis
Servermask