VulnerabilityModified
CVE-2006-1391
The (a) Quick 'n Easy Web Server before 3.1.1 and (b) Baby ASP Web Server 2.7.2 allows remote attackers to obtain the source code of ASP files via (1) .
MEDIUM 5.0EPSS 2.08%
Does this matter?
Lower severity and a low EPSS score (2.08%). Track it; it rarely justifies an emergency change on its own.
Description
The (a) Quick 'n Easy Web Server before 3.1.1 and (b) Baby ASP Web Server 2.7.2 allows remote attackers to obtain the source code of ASP files via (1) . (dot) and (2) space characters in the extension of a URL.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.08% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- pablo software solutions/baby asp web server · pablo software solutions/quick and easy web server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/19306Patch, Vendor Advisory
- http://secunia.com/advisories/19312Vendor Advisory
- http://secunia.com/secunia_research/2006-19/advisory/Patch, Vendor Advisory
- http://securityreason.com/securityalert/624
- http://www.osvdb.org/24099
- http://www.osvdb.org/24100Patch
- http://www.securityfocus.com/archive/1/428667/100/0/threaded
- http://www.securityfocus.com/bid/17222Patch
- http://www.vupen.com/english/advisories/2006/1085
- http://www.vupen.com/english/advisories/2006/1088
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25417
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25418
- http://secunia.com/advisories/19306Patch, Vendor Advisory
- http://secunia.com/advisories/19312Vendor Advisory
- http://secunia.com/secunia_research/2006-19/advisory/Patch, Vendor Advisory
- http://securityreason.com/securityalert/624
- http://www.osvdb.org/24099
- http://www.osvdb.org/24100Patch
- http://www.securityfocus.com/archive/1/428667/100/0/threaded
- http://www.securityfocus.com/bid/17222Patch
- http://www.vupen.com/english/advisories/2006/1085
- http://www.vupen.com/english/advisories/2006/1088
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25417
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25418
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.