2.6

CVE-2006-0704

iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error message that displays the installation path, web server name, IP, and port, session cookie information, and the IIS system username.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IeIe Integrator Version4.4.220114
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.22% 0.647
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/18813
Vendor Advisory
http://www.irmplc.com/advisory016.htm
Vendor Advisory
http://www.vupen.com/english/advisories/2006/0568
https://exchange.xforce.ibmcloud.com/vulnerabilities/24714