PT-2006-1758 · Ie · Ie Integrator
Published
2006-02-15
·
Updated
2017-07-20
·
CVE-2006-0704
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
iE Integrator version 4.4.220114
Description
The issue allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory. This results in an error message that displays the installation path, web server name, IP, and port, session cookie information, and the IIS system username.
Recommendations
For iE Integrator version 4.4.220114, configure a "bespoke error page" in acm.ini to prevent the disclosure of sensitive information.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ie Integrator