First published: Fri Jun 17 2005(Updated: )
Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yaws | =1.50 | |
Yaws | =1.51 | |
Yaws | =1.52 | |
Yaws | =1.53 | |
Yaws | =1.54 | |
Yaws | =1.55 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2008 is classified as a medium severity vulnerability due to its potential for exposing sensitive script source code.
To fix CVE-2005-2008, upgrade Yaws Webserver to version 1.56 or later, which addresses this vulnerability.
CVE-2005-2008 affects Yaws Webserver versions 1.50 to 1.55.
CVE-2005-2008 is a remote code exposure vulnerability that allows attackers to obtain the source code of Yaws scripts.
Yes, CVE-2005-2008 can be exploited remotely by sending specially crafted requests to the Yaws Webserver.