First published: Fri Dec 31 2004(Updated: )
GeoHttpServer, when configured to authenticate users, allows remote attackers to bypass authentication and access unauthorized files via a URL that contains %0a%0a (encoded newlines).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Geovision Geohttpserver |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2100 has a medium severity rating due to its potential to allow unauthorized access.
To fix CVE-2004-2100, ensure that proper input validation is implemented to sanitize user inputs and prevent encoded newline characters.
CVE-2004-2100 affects GeoHttpServer configured for user authentication in specific versions of GeoVision software.
Yes, CVE-2004-2100 can lead to data breaches by allowing attackers bypass authorization and access sensitive files.
There is no specific patch for CVE-2004-2100, but updating to the latest version and applying best security practices is recommended.