PT-2000-1576 · Webactive · Webactive Http Server
Published
2000-07-12
·
Updated
2017-10-10
·
CVE-2000-0642
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WebActive HTTP Server version 1.00
Description
The default configuration of the software stores the web access log active.log in the document root. This allows remote attackers to view the logs by directly requesting the page.
Recommendations
For WebActive HTTP Server version 1.00, consider moving the active.log file to a location outside of the document root to prevent unauthorized access. As a temporary workaround, restrict access to the active.log file until a more permanent solution is implemented.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Webactive Http Server