PT-2004-1136 · Port80+1 · Servermask+1
Martin Oneal
·
Published
2004-08-18
·
Updated
2017-07-11
·
CVE-2003-0105
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ServerMask versions 2.2 and earlier
Description
The issue concerns the lack of obfuscation for certain HTTP responses, specifically (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could reveal to remote attackers that the web server is an IIS server.
Recommendations
For ServerMask versions 2.2 and earlier, consider updating to a version that properly obfuscates these HTTP responses to prevent disclosure of the web server type. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Iis
Servermask