CVE-2004-2213: Medium severity Mbedthis Software Mbedthis Appweb Http Server vulnerability
Published Dec 31, 2004
·Updated
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scripts via a (1) trailing dot (".") or (2) trailing space in an HTTP request.
Affected Software
8 affected components
Mbedthis Software Mbedthis Appweb Http Server=1.0
Mbedthis Software Mbedthis Appweb Http Server=1.0.1
Mbedthis Software Mbedthis Appweb Http Server=1.0.2
Mbedthis Software Mbedthis Appweb Http Server=1.0.3
Mbedthis Software Mbedthis Appweb Http Server=1.0.4
Mbedthis Software Mbedthis Appweb Http Server=1.1
Mbedthis Software Mbedthis Appweb Http Server=1.1.1
Mbedthis Software Mbedthis Appweb Http Server=1.1.2
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jul 17, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2213?
CVE-2004-2213 is considered a medium severity vulnerability due to its ability to expose sensitive source code to remote attackers.
2
How do I fix CVE-2004-2213?
To fix CVE-2004-2213, upgrade the Mbedthis AppWeb HTTP server to version 1.1.3 or later.
3
What types of attacks are possible with CVE-2004-2213?
CVE-2004-2213 allows attackers to obtain the source code for scripts by crafting specific HTTP requests.
4
Which versions are affected by CVE-2004-2213?
CVE-2004-2213 affects Mbedthis AppWeb HTTP server versions 1.0 through 1.1.2.
5
Is CVE-2004-2213 still a risk today?
CVE-2004-2213 poses a risk only to systems running the affected versions of Mbedthis AppWeb HTTP server that have not been updated.