WebSite Pro Malformed URL Path Disclosure

medium Nessus Plugin ID 10303

Synopsis

The remote service is vulnerable to information disclosure.

Description

It was possible to discover the physical location of a virtual web directory of this host by issuing the command :

GET /HTTP1.0/

This can reveal valuable information to an attacker, allowing them to focus their attack.

Solution

Upgrade to Website Pro version 2.5 or later.

See Also

https://seclists.org/bugtraq/2000/Jan/165

https://seclists.org/bugtraq/2001/Mar/271

Plugin Details

Severity: Medium

ID: 10303

File Name: website_pro.nasl

Version: 1.29

Type: remote

Family: CGI abuses

Published: 1/13/2000

Updated: 5/12/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.5

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

Required KB Items: Settings/ThoroughTests

Exploit Ease: No exploit is required

Vulnerability Publication Date: 1/12/2000

Reference Information

CVE: CVE-2000-0066

BID: 932