Red Hat Stronghold 2.3 to 3.0 allows remote attackers to retrieve system information via an HTTP GET request to (1) stronghold-info or (2) stronghold-status.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/3577 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/51951 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7582 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/51950 | vdb entry |
http://marc.info/?l=bugtraq&m=100654958131854&w=2 | mailing list |