PT-2006-1758 · Ie · Ie Integrator

Published

2006-02-15

·

Updated

2017-07-20

·

CVE-2006-0704

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions iE Integrator version 4.4.220114
Description The issue allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory. This results in an error message that displays the installation path, web server name, IP, and port, session cookie information, and the IIS system username.
Recommendations For iE Integrator version 4.4.220114, configure a "bespoke error page" in acm.ini to prevent the disclosure of sensitive information.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0704

Affected Products

Ie Integrator