VulnerabilityModified
CVE-2006-1483
Blazix Web Server before 1.2.6, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) .
MEDIUM 5.0EPSS 1.94%
Does this matter?
Lower severity and a low EPSS score (1.94%). Track it; it rarely justifies an emergency change on its own.
Description
Blazix Web Server before 1.2.6, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot), (2) space, and (3) slash characters in the extension of a URL.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.94% probability · 79th percentile
- CISA KEV
- Not listed
- Affected
- desiderata software/blazix web server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/19341Patch, Vendor Advisory
- http://secunia.com/secunia_research/2006-22/advisory/Patch, Vendor Advisory
- http://securityreason.com/securityalert/643
- http://securitytracker.com/id?1015837
- http://www.osvdb.org/24178
- http://www.securityfocus.com/archive/1/429108/100/0/threaded
- http://www.securityfocus.com/bid/17270Patch
- http://www.vupen.com/english/advisories/2006/1133
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25485
- http://secunia.com/advisories/19341Patch, Vendor Advisory
- http://secunia.com/secunia_research/2006-22/advisory/Patch, Vendor Advisory
- http://securityreason.com/securityalert/643
- http://securitytracker.com/id?1015837
- http://www.osvdb.org/24178
- http://www.securityfocus.com/archive/1/429108/100/0/threaded
- http://www.securityfocus.com/bid/17270Patch
- http://www.vupen.com/english/advisories/2006/1133
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25485
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.