3.5
CVE-2011-1424
- EPSS 0.77%
- Veröffentlicht 24.05.2011 23:55:02
- Zuletzt bearbeitet 16.06.2026 23:29:19
- Erkennungen
The default configuration of ExShortcut\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the trace element, which allows remote authenticated users to obtain sensitive information via ASP.NET Application Tracing.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emc ≫ Sourceone Email Management Version <= 6.6.0.1209
Emc ≫ Sourceone Email Management Version 6.5.2.3668
Emc ≫ Sourceone Email Management Version <= 6.6.0.1209
Emc ≫ Sourceone Email Management Version 6.5.2.3668
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.77% | 0.509 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:P/I:N/A:N
|
http://securityreason.com/securityalert/8258
http://www.securityfocus.com/archive/1/518003/100/0/threaded