iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error message that displays the installation path, web server name, IP, and port, session cookie information, and the IIS system username.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T16:41:29.203Z
Reserved: 2006-02-15T00:00:00
Link: CVE-2006-0704

No data.

Status : Deferred
Published: 2006-02-15T11:06:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2006-0704

No data.