CVE-2003-0456: Infoleak
VisNetic WebSite 3.5 allows remote attackers to obtain the full pathname of the server via a request containing a folder that does not exist, which leaks the pathname in an error message, as demonstrated using vtibin/fpcount.exe.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0456?
CVE-2003-0456 is considered a low severity vulnerability as it primarily exposes the server pathname via error messages.
How does CVE-2003-0456 affect the VisNetic WebSite?
CVE-2003-0456 allows remote attackers to infer the server's full pathname through crafted requests that elicit error messages.
Which versions of VisNetic WebSite are affected by CVE-2003-0456?
CVE-2003-0456 affects VisNetic WebSite versions 3.5.13, 3.5.15, and 3.5.17.
How do I fix CVE-2003-0456?
To fix CVE-2003-0456, ensure that your version of VisNetic WebSite is updated to a secure version that does not leak error messages.
What is the exploit method for CVE-2003-0456?
CVE-2003-0456 can be exploited by making requests to non-existent folders, which results in the server revealing its directory structure in error messages.