PT-2004-2075 · Mailpost · Mailpost
Published
2004-12-01
·
Updated
2017-07-11
·
CVE-2004-1103
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
MailPost versions 5.1.1sv and earlier
Description:
The issue allows remote attackers to gain sensitive information when debug mode is enabled. This is achieved via the
debug parameter, which reveals information such as the path to the web root and the web server version.Recommendations:
For MailPost versions 5.1.1sv and earlier, disable the debug mode to prevent the disclosure of sensitive information. As a temporary workaround, consider restricting access to the debug parameter until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mailpost