CVE-2003-1408: Infoleak
Published Dec 31, 2003
·Updated
Lotus Domino Server 5.0 and 6.0 allows remote attackers to read the source code for files via an HTTP request with a filename with a trailing dot.
Affected Software
2 affected components
Lotus Domino Server=5.0
Lotus Domino Server=6.0
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 20, 2007
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1408?
CVE-2003-1408 is considered a medium severity vulnerability.
2
How does CVE-2003-1408 affect Lotus Domino Server?
CVE-2003-1408 allows remote attackers to read the source code of files through specially crafted HTTP requests.
3
Which versions of Lotus Domino Server are affected by CVE-2003-1408?
CVE-2003-1408 affects Lotus Domino Server versions 5.0 and 6.0.
4
How can I mitigate CVE-2003-1408?
To mitigate CVE-2003-1408, ensure that your server is upgraded to a patched version that does not allow source code exposure.
5
What is the attack vector for CVE-2003-1408?
The attack vector for CVE-2003-1408 is through an HTTP request with a filename that includes a trailing dot.