VulnerabilityModified
CVE-2003-0105
ServerMask 2.2 and earlier does not obfuscate (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could tell remote attackers that the web server is an IIS server.
MEDIUM 5.0EPSS 2.58%
Does this matter?
Lower severity and a low EPSS score (2.58%). Track it; it rarely justifies an emergency change on its own.
Description
ServerMask 2.2 and earlier does not obfuscate (1) ETag, (2) HTTP Status Message, or (3) Allow HTTP responses, which could tell remote attackers that the web server is an IIS server.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.58% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- port80 software/servermask
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=109215441332682&w=2
- http://www.corsaire.com/advisories/c030224-001.txtVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16947
- http://marc.info/?l=bugtraq&m=109215441332682&w=2
- http://www.corsaire.com/advisories/c030224-001.txtVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16947
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.