7.5
CVSSv3

CVE-2007-3365

Published: 22/06/2007 Updated: 08/02/2024
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

MyServer 0.8.9 and previous versions does not properly handle uppercase characters in filename extensions, which allows remote malicious users to obtain sensitive information (script source code) via a modified extension, as demonstrated by post.mscgI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

myserverproject myserver

Exploits

source: wwwsecurityfocuscom/bid/24571/info MyServer is prone to an information-disclosure vulnerability An attacker can exploit this issue to access sensitive information that may lead to further attacks This issue affects MyServer 089; other versions may also be affected wwwexamplecom/cgi-bin/postmscgI (Note: Capital 'I ...