The Administration console for Abyss Web Server 1.0.3 before Patch 2 allows remote attackers to gain privileges and modify server configuration via direct requests to CHL files such as (1) srvstatus.chl, (2) consport.chl, (3) general.chl, (4) srvparam.chl, and (5) advanced.chl.
References
Link | Resource |
---|---|
http://www.iss.net/security_center/static/9957.php | Patch Vendor Advisory |
http://www.securityfocus.com/bid/5548 | Exploit Patch Vendor Advisory |
http://archives.neohapsis.com/archives/bugtraq/2002-08/0229.html | |
http://www.aprelium.com/news/patch1033.html |
Configurations
Configuration 1 (hide)
|
Information
Published : 2002-10-03 21:00
Updated : 2008-09-05 13:29
NVD link : CVE-2002-1080
Mitre link : CVE-2002-1080
JSON object : View
CWE
Products Affected
aprelium_technologies
- abyss_web_server