PT-2004-1136 · Port80+1 · Servermask+1
Martin Oneal
·
Publicado
2004-08-18
·
Atualizado
2017-07-11
·
CVE-2003-0105
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ServerMask versions 2.2 and earlier
Description
The issue concerns the lack of obfuscation for certain HTTP responses, specifically (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could reveal to remote attackers that the web server is an IIS server.
Recommendations
For ServerMask versions 2.2 and earlier, consider updating to a version that properly obfuscates these HTTP responses to prevent disclosure of the web server type. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Iis
Servermask