The Administration console for Abyss Web Server 1.0.3 before Patch 2 allows remote attackers to gain privileges and modify server configuration via direct requests to CHL files such as (1) srvstatus.chl, (2) consport.chl, (3) general.chl, (4) srvparam.chl, and (5) advanced.chl.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Abyss_web_server | Aprelium_technologies | 1.0 (including) | 1.0 (including) |
Abyss_web_server | Aprelium_technologies | 1.0.3 (including) | 1.0.3 (including) |