PT-2002-2450 · Asksam · Asksam Web Publisher
Published
2002-12-31
·
Updated
2017-07-11
·
CVE-2002-1728
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
askSam Web Publisher versions 1.0 through 4.0
Description
The issue allows remote attackers to determine the full path to the web root directory. This is achieved by requesting a file that does not exist, which generates an error message revealing the full path.
Recommendations
For askSam Web Publisher versions 1.0 through 4.0, consider restricting access to error messages that may reveal sensitive information about the web root directory until a fix is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Asksam Web Publisher