Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gv97-jrx5-pj3x

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The default configuration of ExShortcut\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the trace element, which allows remote authenticated users to obtain sensitive information via ASP.NET Application Tracing.

The default configuration of ExShortcut\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the trace element, which allows remote authenticated users to obtain sensitive information via ASP.NET Application Tracing.

EPSS

Процентиль: 38%
0.00162
Низкий

Связанные уязвимости

nvd
больше 14 лет назад

The default configuration of ExShortcut\Web.config in EMC SourceOne Email Management before 6.6 SP1, when the Mobile Services component is used, does not properly set the localOnly attribute of the trace element, which allows remote authenticated users to obtain sensitive information via ASP.NET Application Tracing.

EPSS

Процентиль: 38%
0.00162
Низкий