VulnerabilityModified
CVE-1999-1418
ICQ99 ICQ web server build 1701 with "Active Homepage" enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists ("404 Forbidden") versus when a file does not exist ("404…
MEDIUM 5.0EPSS 1.31%
Does this matter?
Lower severity and a low EPSS score (1.31%). Track it; it rarely justifies an emergency change on its own.
Description
ICQ99 ICQ web server build 1701 with "Active Homepage" enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists ("404 Forbidden") versus when a file does not exist ("404 not found").
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.31% probability · 69th percentile
- CISA KEV
- Not listed
- Affected
- mirabilis/icq web front
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/13508Patch, Vendor Advisory
- http://www.securityfocus.com/bid/246
- http://www.securityfocus.com/archive/1/13508Patch, Vendor Advisory
- http://www.securityfocus.com/bid/246
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.