Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-crw8-5r9p-8x8x

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which returns different HTTP status codes for existing and non-existing directories.

The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which returns different HTTP status codes for existing and non-existing directories.

EPSS

Процентиль: 92%
0.07366
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
больше 19 лет назад

The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which returns different HTTP status codes for existing and non-existing directories.

EPSS

Процентиль: 92%
0.07366
Низкий

Дефекты

CWE-200