Vulnerability Description
index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to obtain the full server path via an invalid VDNS_Sessid parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vegadns | Vegadns | 0.8.1 |
References
- http://secunia.com/advisories/16370Vendor Advisory
- http://vegadns.org/src/current/CHANGELOG
- http://www.packetstormsecurity.org/0508-exploits/vegadns-dyn0.txtExploit
- http://secunia.com/advisories/16370Vendor Advisory
- http://vegadns.org/src/current/CHANGELOG
- http://www.packetstormsecurity.org/0508-exploits/vegadns-dyn0.txtExploit
FAQ
What is CVE-2005-2609?
CVE-2005-2609 is a vulnerability with a CVSS score of 5.0 (MEDIUM). index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to obtain the full server path via an invalid VDNS_Sessid parameter.
How severe is CVE-2005-2609?
CVE-2005-2609 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-2609?
Check the references section above for vendor advisories and patch information. Affected products include: Vegadns Vegadns.