CVE-2003-1306
Last modified
CVE-2003-1306 is a vulnerability of currently unknown severity. Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in the response.. EPSS estimates a 1.20% chance of exploitation in the next 30 days.
Description
Microsoft URLScan 2.5, with the RemoveServerHeader option enabled, allows remote attackers to obtain sensitive information (server name and version) via an HTTP request that generates certain errors such as 400 "Bad Request," which leak the Server header in the response.
Metrics
References
- http://secunia.com/advisories/9194Vendor Advisory
- http://www.osvdb.org/29370Exploit
- http://secunia.com/advisories/9194Vendor Advisory
- http://www.osvdb.org/29370Exploit
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-1306?
How severe is CVE-2003-1306?
How do I fix CVE-2003-1306?
Are you affected by CVE-2003-1306?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
