The Administration console for Abyss Web Server 1.0.3 before Patch 2 allows remote attackers to gain privileges and modify server configuration via direct requests to CHL files such as (1) srvstatus.chl, (2) consport.chl, (3) general.chl, (4) srvparam.chl, and (5) advanced.chl.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2002-08/0229.html | |
http://www.aprelium.com/news/patch1033.html | |
http://www.iss.net/security_center/static/9957.php | Patch Vendor Advisory |
http://www.securityfocus.com/bid/5548 | Exploit Patch Vendor Advisory |
http://archives.neohapsis.com/archives/bugtraq/2002-08/0229.html | |
http://www.aprelium.com/news/patch1033.html | |
http://www.iss.net/security_center/static/9957.php | Patch Vendor Advisory |
http://www.securityfocus.com/bid/5548 | Exploit Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:40
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2002-08/0229.html - | |
References | () http://www.aprelium.com/news/patch1033.html - | |
References | () http://www.iss.net/security_center/static/9957.php - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/5548 - Exploit, Patch, Vendor Advisory |
Information
Published : 2002-10-04 04:00
Updated : 2024-11-20 23:40
NVD link : CVE-2002-1080
Mitre link : CVE-2002-1080
CVE.ORG link : CVE-2002-1080
JSON object : View
Products Affected
aprelium_technologies
- abyss_web_server
CWE