CVE-2002-0596
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
18/06/2002
Last modified:
03/04/2025
Description
WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl with an empty Profile parameter, which leaks the pathname in an error message.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:webtrends:reporting_center:4.0d:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0207.html
- http://www.iss.net/security_center/static/8865.php
- http://www.ngssoftware.com/advisories/wtr.txt
- http://www.osvdb.org/10447
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0207.html
- http://www.iss.net/security_center/static/8865.php
- http://www.ngssoftware.com/advisories/wtr.txt
- http://www.osvdb.org/10447