PT-2006-1758 · Ie · Ie Integrator
Publicado
2006-02-15
·
Atualizado
2017-07-20
·
CVE-2006-0704
CVSS v2.0
2.6
Baixa
| Vetor | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
iE Integrator version 4.4.220114
Description
The issue allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory. This results in an error message that displays the installation path, web server name, IP, and port, session cookie information, and the IIS system username.
Recommendations
For iE Integrator version 4.4.220114, configure a "bespoke error page" in acm.ini to prevent the disclosure of sensitive information.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ie Integrator