PT-2002-2401 · Unknown · Mrtgconfig

Published

2002-12-31

·

Updated

2017-07-11

·

CVE-2002-1677

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions mrtgconfig versions 1.1p15
Description The issue allows remote attackers to determine the physical path to the web root directory. This is achieved by sending a request with an invalid cfg parameter to the 14all.cgi script, which generates an error message that reveals the path.
Recommendations For version 1.1p15, consider restricting access to the 14all.cgi script until a patch is available. As a temporary workaround, avoid using the cfg parameter in the affected script to minimize the risk of path disclosure.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1677

Affected Products

Mrtgconfig