4
CVE-2006-2309
- EPSS 1.58%
- Veröffentlicht 02.06.2006 00:02:00
- Zuletzt bearbeitet 16.06.2026 22:24:45
- Quelle PSIRT-CNA@flexerasoftware.com
- CVE-Watchlists
- Unerledigt
The HTTP service in EServ/3 3.25 allows remote attackers to obtain sensitive information via crafted HTTP requests containing dot, space, and slash characters, which reveals the source code of script files.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.58% | 0.723 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
http://secunia.com/advisories/20059
http://secunia.com/secunia_research/2006-37/advisory/
http://securityreason.com/securityalert/1006
http://www.eserv.ru/ru/news/news_detail.php?ID=235
http://www.securityfocus.com/archive/1/435415/100/0/threaded
http://www.securityfocus.com/bid/18179
http://www.vupen.com/english/advisories/2006/2066
https://exchange.xforce.ibmcloud.com/vulnerabilities/26741