First published: Fri Dec 31 2004(Updated: )
Information leak in Mbedthis AppWeb HTTP server 1.0 through 1.1.2 allows remote attackers to obtain sensitive information via a user message that is generated when Mbedthis denies access.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mbedthis AppWeb HTTP server | =1.0.2 | |
Mbedthis AppWeb HTTP server | =1.0.4 | |
Mbedthis AppWeb HTTP server | =1.0.1 | |
Mbedthis AppWeb HTTP server | =1.1.2 | |
Mbedthis AppWeb HTTP server | =1.1.1 | |
Mbedthis AppWeb HTTP server | =1.0.3 | |
Mbedthis AppWeb HTTP server | =1.1 | |
Mbedthis AppWeb HTTP server | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2317 is classified as a moderate severity vulnerability due to its potential for information leakage.
CVE-2004-2317 affects Mbedthis AppWeb HTTP server versions 1.0 through 1.1.2 inclusive.
To fix CVE-2004-2317, upgrade to a later version of Mbedthis AppWeb HTTP server that is not affected, specifically version 1.1.3 or later.
CVE-2004-2317 is an information leak vulnerability that allows attackers to obtain sensitive information through access denial messages.
Users of Mbedthis AppWeb HTTP server 1.0 to 1.1.2 are at risk from CVE-2004-2317 due to potential exposure of sensitive information.