First published: Mon May 15 2006(Updated: )
Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium allows remote attackers to obtain full path information via 404 error messages. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ipswitch WhatsUp | =2006 | |
Ipswitch WhatsUp | =2006_premium |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2355 is considered to have a low severity level as it allows attackers to obtain full path information through error messages.
To fix CVE-2006-2355, ensure that your Ipswitch WhatsUp Professional software is updated to the latest version to mitigate path disclosure vulnerabilities.
CVE-2006-2355 affects Ipswitch WhatsUp Professional versions 2006 and 2006 Premium.
While CVE-2006-2355 itself is a path disclosure issue, it can potentially assist attackers in conducting more targeted attacks if they gather sensitive information.
CVE-2006-2355 is not commonly exploited but indicates a typical misconfiguration issue that can occur in many web applications.