PT-2004-2860 · Unknown · Network Query Tool

Janek Vind

+1

·

Publicado

2004-04-23

·

Atualizado

2017-07-11

·

CVE-2004-1963

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Network Query Tool (NQT) version 1.6
Description The issue allows remote attackers to obtain sensitive information. This is achieved by manipulating a string in the portNum parameter, which in turn reveals the full path in an error message.
Recommendations For Network Query Tool (NQT) version 1.6, avoid using the portNum parameter in the nqt.php file until the issue is resolved. As a temporary workaround, consider restricting access to the nqt.php file to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1963

Produtos afetados

Network Query Tool