MEDIUM · 5.0

CVE-2008-0407

HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more diffi...

Vulnerability Description

HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administrator to determine who made a remote request.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HfsHttp File Server<= 2.2b

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-0407?

CVE-2008-0407 is a vulnerability with a CVSS score of 5.0 (MEDIUM). HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more diffi...

How severe is CVE-2008-0407?

CVE-2008-0407 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-0407?

Check the references section above for vendor advisories and patch information. Affected products include: Hfs Http File Server.