PT-2002-2450 · Asksam · Asksam Web Publisher

Published

2002-12-31

·

Updated

2017-07-11

·

CVE-2002-1728

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions askSam Web Publisher versions 1.0 through 4.0
Description The issue allows remote attackers to determine the full path to the web root directory. This is achieved by requesting a file that does not exist, which generates an error message revealing the full path.
Recommendations For askSam Web Publisher versions 1.0 through 4.0, consider restricting access to error messages that may reveal sensitive information about the web root directory until a fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1728

Affected Products

Asksam Web Publisher