|
|||
Rule General Information |
---|
Release Date: | 2017-07-25 | |
Rule Name: | WEB-OTHER GoAhead login.cgi Information Disclosure Vulnerability | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malformed HTTP ("GET login.cgi HTTP/1.1\n\n" - note the lack of "/" in the path field of the request) request that will disclose the configuration file with the login password. | |
Impact: | Information disclosure | |
Affected OS: | Others | |
Reference: | ||
Solutions |
---|
Update vendor's patch. |