Unrated severityNVD Advisory· Published Aug 18, 2003· Updated Apr 16, 2026
CVE-2003-0456
CVE-2003-0456
Description
VisNetic WebSite 3.5 allows remote attackers to obtain the full pathname of the server via a request containing a folder that does not exist, which leaks the pathname in an error message, as demonstrated using _vti_bin/fpcount.exe.
Affected products
3cpe:2.3:a:deerfield:visnetic_website:3.5.13:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:deerfield:visnetic_website:3.5.13:*:*:*:*:*:*:*
- cpe:2.3:a:deerfield:visnetic_website:3.5.15:*:*:*:*:*:*:*
- cpe:2.3:a:deerfield:visnetic_website:3.5.17:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.securityfocus.com/bid/8075nvdPatchVendor Advisory
- archives.neohapsis.com/archives/vulnwatch/2003-q3/0002.htmlnvdExploitPatchVendor Advisory
- marc.infonvd
- www.krusesecurity.dk/advisories/vis0103.txtnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/12483nvd
News mentions
0No linked articles in our index yet.