Vulnerability Description
Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yaws | Webserver | 1.50 |
References
- http://marc.info/?l=bugtraq&m=111927717726371&w=2
- http://secunia.com/advisories/15740PatchVendor Advisory
- http://www.osvdb.org/17375Vendor Advisory
- http://yaws.hyber.org/yaws-1.55_to_1.56.patchPatchVendor Advisory
- http://marc.info/?l=bugtraq&m=111927717726371&w=2
- http://secunia.com/advisories/15740PatchVendor Advisory
- http://www.osvdb.org/17375Vendor Advisory
- http://yaws.hyber.org/yaws-1.55_to_1.56.patchPatchVendor Advisory
FAQ
What is CVE-2005-2008?
CVE-2005-2008 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).
How severe is CVE-2005-2008?
CVE-2005-2008 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-2008?
Check the references section above for vendor advisories and patch information. Affected products include: Yaws Webserver.