PT-2006-1758 · Ie · Ie Integrator

Publicado

2006-02-15

·

Atualizado

2017-07-20

·

CVE-2006-0704

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions iE Integrator version 4.4.220114
Description The issue allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory. This results in an error message that displays the installation path, web server name, IP, and port, session cookie information, and the IIS system username.
Recommendations For iE Integrator version 4.4.220114, configure a "bespoke error page" in acm.ini to prevent the disclosure of sensitive information.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0704

Produtos afetados

Ie Integrator