PT-2004-2886 · Aldo · Aldo'S Web Server
Publicado
2004-03-03
·
Atualizado
2017-07-11
·
CVE-2004-1990
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Aldo's Web Server (aweb) version 1.5
Description
The issue allows remote attackers to gain sensitive information via an arbitrary character, which reveals the full path and the user running the aweb process, possibly due to a malformed request.
Recommendations
For version 1.5, consider restricting access to sensitive information until a patch is available. As a temporary workaround, review and sanitize all input to prevent malformed requests from being processed.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Aldo'S Web Server