PT-2004-2465 · Mywebserver · Mywebserver

Nekd0

·

Publicado

2004-12-31

·

Atualizado

2017-07-11

·

CVE-2004-1557

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions MyWebServer version 1.0.3
Description The issue allows remote attackers to bypass authentication, modify configuration, and read arbitrary files. This can be achieved via a direct HTTP request to API endpoints such as "/admin" or "ServerProperties.html".
Recommendations For MyWebServer version 1.0.3, consider restricting access to the "/admin" and "ServerProperties.html" API endpoints to prevent unauthorized modifications and file access. As a temporary workaround, limit the functionality of these endpoints until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1557

Produtos afetados

Mywebserver