CVE-2003-1242: Medium severity Sage Sage vulnerability
Published Dec 31, 2003
·Updated
Sage 1.0 b3 allows remote attackers to obtain the root web server path via a URL request for a non-existent module, which returns the path in an error message.
Affected Software
2 affected components
Sage Sage=1.0_beta_3
Sage Sage=1.0_beta_3
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Nov 16, 2005
CVE Published
via MITRE·07:37 AM
Data Sourced
via MITRE·07:37 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1242?
CVE-2003-1242 is considered a medium severity vulnerability due to its potential exposure of sensitive filesystem paths.
2
How do I fix CVE-2003-1242?
To fix CVE-2003-1242, ensure that the web application does not disclose error messages that reveal the server's filesystem paths.
3
Who is affected by CVE-2003-1242?
CVE-2003-1242 affects users of Sage version 1.0 beta 3.
4
What does CVE-2003-1242 expose?
CVE-2003-1242 exposes the root web server path through error messages when an invalid module is requested.
5
When was CVE-2003-1242 disclosed?
CVE-2003-1242 was disclosed in February 2003 and is associated with a vulnerability in a specific version of Sage.