CVE-2005-2008
Published Jun 17, 2005
Last updated 8 years ago
Overview
- Description
- Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:yaws:webserver:1.50:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CF9408BC-32C2-4F56-B8AB-B5C5B658565F" }, { "criteria": "cpe:2.3:a:yaws:webserver:1.51:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "99CF38D0-9CE7-4166-9E50-528D159A7FC8" }, { "criteria": "cpe:2.3:a:yaws:webserver:1.52:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C11008F6-D5A9-46D4-BBB4-1813977BB072" }, { "criteria": "cpe:2.3:a:yaws:webserver:1.53:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C5B8A3D1-AB3F-418E-91AF-5DBBD7750438" }, { "criteria": "cpe:2.3:a:yaws:webserver:1.54:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "59DA8476-D330-4462-99F4-7C5DCC1B2513" }, { "criteria": "cpe:2.3:a:yaws:webserver:1.55:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BE17FA92-81D8-4557-B1E7-26998CD3ED54" } ], "operator": "OR" } ] } ]