First published: Tue Apr 25 2006(Updated: )
Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the information via direct requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Symantec AntiVirus Scan Engine | =5.0.0.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.