PT-2001-1966 · Igss · Air Messenger Lan Server

Published

2001-10-12

·

Updated

2008-09-05

·

CVE-2001-0788

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Air Messenger LAN Server version 3.4.2
Description The issue allows remote attackers to obtain the absolute path for the server directory. This is achieved by viewing the Location header.
Recommendations For Air Messenger LAN Server version 3.4.2, consider restricting access to sensitive server directories until a patch is available. As a temporary workaround, modify server configurations to prevent the disclosure of the server directory path in the Location header.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0788

Affected Products

Air Messenger Lan Server