Vulnerability CVE-2006-1598


Published: 2006-04-03   Modified: 2012-02-12

Description:
AN HTTPD 1.42n, and possibly other versions before 1.42p, allows remote attackers to obtain source code of scripts via crafted requests with (1) dot and (2) space characters in the file extension.

Type:

CWE-Other

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.8/10
6.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
None
None
Affected software
AN -> An-httpd 

 References:
http://securitytracker.com/id?1015858
http://www.securityfocus.com/archive/1/429667/100/0/threaded
http://www.securityfocus.com/bid/17350
http://www.vupen.com/english/advisories/2006/1200
https://exchange.xforce.ibmcloud.com/vulnerabilities/25591

Copyright 2021, cxsecurity.com

 

Back to Top