PT-2004-2075 · Mailpost · Mailpost

Publicado

2004-12-01

·

Atualizado

2017-07-11

·

CVE-2004-1103

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: MailPost versions 5.1.1sv and earlier
Description: The issue allows remote attackers to gain sensitive information when debug mode is enabled. This is achieved via the debug parameter, which reveals information such as the path to the web root and the web server version.
Recommendations: For MailPost versions 5.1.1sv and earlier, disable the debug mode to prevent the disclosure of sensitive information. As a temporary workaround, consider restricting access to the debug parameter until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1103

Produtos afetados

Mailpost