PT-2003-2251 · Microsoft · Urlscan
Published
2003-12-31
·
Updated
2008-09-05
·
CVE-2003-1306
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft URLScan version 2.5
Description
The issue allows remote attackers to obtain sensitive information, including the server name and version, via specific HTTP requests that generate certain errors, such as a 400 "Bad Request" error, which can leak the Server header in the response.
Recommendations
For Microsoft URLScan version 2.5, consider disabling the RemoveServerHeader option as a temporary workaround to minimize the risk of information leakage.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Urlscan