PT-2002-2401 · Unknown · Mrtgconfig
Published
2002-12-31
·
Updated
2017-07-11
·
CVE-2002-1677
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
mrtgconfig versions 1.1p15
Description
The issue allows remote attackers to determine the physical path to the web root directory. This is achieved by sending a request with an invalid
cfg parameter to the 14all.cgi script, which generates an error message that reveals the path.Recommendations
For version 1.1p15, consider restricting access to the 14all.cgi script until a patch is available. As a temporary workaround, avoid using the
cfg parameter in the affected script to minimize the risk of path disclosure.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mrtgconfig