First published: Mon Jun 04 2007(Updated: )
Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-3398.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mbedthis AppWeb HTTP server | =2.0.2 | |
Mbedthis AppWeb HTTP server | =2.0.0 | |
Mbedthis AppWeb HTTP server | =2.1.0 | |
Mbedthis AppWeb HTTP server | =2.0.4 | |
Mbedthis AppWeb HTTP server | =2.2.0 | |
Mbedthis AppWeb HTTP server | =2.2.1 | |
Mbedthis AppWeb HTTP server | =2.0.5 | |
Mbedthis AppWeb HTTP server | =2.0.3 | |
Mbedthis AppWeb HTTP server | =2.1.1 | |
Mbedthis AppWeb HTTP server | =2.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2007-3008 is not explicitly rated but it poses risks related to remote information leaks and cross-site tracing attacks.
To fix CVE-2007-3008, you should upgrade to Mbedthis AppWeb version 2.2.2 or later, which disables the HTTP TRACE method.
Versions 2.0.0 to 2.2.1 of Mbedthis AppWeb HTTP server are affected by CVE-2007-3008.
CVE-2007-3008 can enable remote information leaks and make systems vulnerable to cross-site tracing (XST) attacks.
Yes, CVE-2007-3008 is related to CVE-2004-2320 and CVE-2005-3398 regarding similar risks associated with HTTP methods.