PT-2005-1364 · Emotion · Emotion Mediapartner Web Server
Paul J Docherty
·
Publicado
2005-02-10
·
Atualizado
2017-07-11
·
CVE-2005-0286
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
eMotion MediaPartner Web Server versions 5.0 through 5.1
Description
The issue allows remote attackers to obtain sensitive information via an HTTP request for a .bhtml file. This can happen when the file contains a
dot (.) or a plus sign (+) at the end, which then returns the source code for that file.Recommendations
For versions 5.0 through 5.1, consider restricting access to .bhtml files to minimize the risk of exploitation. As a temporary workaround, avoid using .bhtml files that contain a
dot (.) or a plus sign (+) at the end until a fix is available.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Emotion Mediapartner Web Server