CVE Vulnerabilities

CVE-2003-1306

Published: Dec 31, 2003 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 Bad Request, which leak the Server header in the response.

Affected Software

Name Vendor Start Version End Version
Urlscan Microsoft 2.5 2.5

References