NetworkActiv Web Server Remote Script Disclosure Vulnerability
BID:16895
Info
NetworkActiv Web Server Remote Script Disclosure Vulnerability
| Bugtraq ID: | 16895 |
| Class: | Design Error |
| CVE: |
CVE-2006-0815 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 01 2006 12:00AM |
| Updated: | Mar 05 2006 02:11AM |
| Credit: | Discovered by Tan Chew Keong, Secunia Research. |
| Vulnerable: |
NetworkActiv NetworkActiv Web Server 3.5.15 NetworkActiv NetworkActiv Web Server 3.5.14 NetworkActiv NetworkActiv Web Server 3.5.13 NetworkActiv NetworkActiv Web Server 3.0.1 .1 |
| Not Vulnerable: |
NetworkActiv NetworkActiv Web Server 3.5.16 |
Discussion
NetworkActiv Web Server Remote Script Disclosure Vulnerability
NetworkActiv Web Server is prone to an information-disclosure vulnerability. An attacker may obtain the source code of script files.
Scripts may contain sensitive information that may aid in further attacks launched against the target computer.
NetworkActiv Web Server versions prior to 3.5.16 are vulnerable.
NetworkActiv Web Server is prone to an information-disclosure vulnerability. An attacker may obtain the source code of script files.
Scripts may contain sensitive information that may aid in further attacks launched against the target computer.
NetworkActiv Web Server versions prior to 3.5.16 are vulnerable.
Exploit / POC
NetworkActiv Web Server Remote Script Disclosure Vulnerability
This issue can be exploited with a web browser.
This issue can be exploited with a web browser.
Solution / Fix
NetworkActiv Web Server Remote Script Disclosure Vulnerability
Solution:
The vendor has reportedly released version 3.5.16 to address this issue. Please see references for more information.
Solution:
The vendor has reportedly released version 3.5.16 to address this issue. Please see references for more information.
References
NetworkActiv Web Server Remote Script Disclosure Vulnerability
References:
References:
- NetworkActiv Web Server Product Page (NetworkActiv)
- Secunia Research: NetworkActiv Web Server Script Source Disclosure Vulnerability (Secunia Research
)