The SSL server in AEP Smartgate 4.3b allows remote malicious users to determine existence of directories via a direct request for a directory URI, which returns different HTTP status codes for existing and non-existing directories.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
aep networks smartgate ssl server 4.3b |