First published: Thu Dec 31 2009(Updated: )
Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending ::$DATA to the URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cesanta Mongoose | <=2.8 | |
Cesanta Mongoose | =2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4530 is considered to have a medium severity due to the potential exposure of sensitive source code.
To fix CVE-2009-4530, upgrade to Mongoose version 2.9.0 or later, which addresses this vulnerability.
Mongoose versions 2.8.0 and earlier are affected by CVE-2009-4530.
CVE-2009-4530 allows remote attackers to disclose the source code of web pages served by the Mongoose web server.
A potential workaround for CVE-2009-4530 is to configure the server to disallow URIs that include ::$DATA.