PT-2005-1364 · Emotion · Emotion Mediapartner Web Server

Paul J Docherty

·

Publicado

2005-02-10

·

Atualizado

2017-07-11

·

CVE-2005-0286

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions eMotion MediaPartner Web Server versions 5.0 through 5.1
Description The issue allows remote attackers to obtain sensitive information via an HTTP request for a .bhtml file. This can happen when the file contains a dot (.) or a plus sign (+) at the end, which then returns the source code for that file.
Recommendations For versions 5.0 through 5.1, consider restricting access to .bhtml files to minimize the risk of exploitation. As a temporary workaround, avoid using .bhtml files that contain a dot (.) or a plus sign (+) at the end until a fix is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0286

Produtos afetados

Emotion Mediapartner Web Server