PT-2004-2785 · Ada · Ada Image Server
Donato Ferrante
·
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-1887
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ada Image Server (ImgSvr) version 0.4
Description
The issue allows remote attackers to view directories or download files by sending an HTTP request with a trailing %00 (null).
Recommendations
For Ada Image Server (ImgSvr) version 0.4, consider restricting access to sensitive directories and files as a temporary workaround until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ada Image Server