Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-3398.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.mbedthis.com/products/appWeb/doc/product/newFeatures.html | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34854 | vdb entry |
http://www.securityfocus.com/bid/24456 | vdb entry |
http://www.osvdb.org/35511 | vdb entry |
http://secunia.com/advisories/25636 | third party advisory vendor advisory |
http://www.appwebserver.org/forum/viewtopic.php?t=996 |