PT-2001-1966 · Igss · Air Messenger Lan Server
Published
2001-10-12
·
Updated
2008-09-05
·
CVE-2001-0788
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Air Messenger LAN Server version 3.4.2
Description
The issue allows remote attackers to obtain the absolute path for the server directory. This is achieved by viewing the Location header.
Recommendations
For Air Messenger LAN Server version 3.4.2, consider restricting access to sensitive server directories until a patch is available. As a temporary workaround, modify server configurations to prevent the disclosure of the server directory path in the Location header.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Air Messenger Lan Server