CVE-2006-0704

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/02/2006
Last modified:
20/07/2017

Description

iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error message that displays the installation path, web server name, IP, and port, session cookie information, and the IIS system username.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ie:ie_integrator:4.4.220114:*:*:*:*:*:*:*