Vulnerability Description
AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displays the server's /var/log/messages file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Axis | 2400 Video Server | 2.0 |
| Axis | 2401 Video Server | 2.20 |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/bugtraq/2003-02/0377.html
- http://archives.neohapsis.com/archives/bugtraq/2003-03/0370.html
- http://www.securityfocus.com/bid/6980
- http://www.websec.org/adv/axis2400.txt.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11440
- http://archives.neohapsis.com/archives/bugtraq/2003-02/0377.html
- http://archives.neohapsis.com/archives/bugtraq/2003-03/0370.html
- http://www.securityfocus.com/bid/6980
- http://www.websec.org/adv/axis2400.txt.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11440
FAQ
What is CVE-2003-1386?
CVE-2003-1386 is a vulnerability with a CVSS score of 6.4 (MEDIUM). AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which displays the server's /var/log/messages file.
How severe is CVE-2003-1386?
CVE-2003-1386 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-1386?
Check the references section above for vendor advisories and patch information. Affected products include: Axis 2400 Video Server, Axis 2401 Video Server.