peter bassill · operator
$ cve CVE-2006-5725 JSON

CVE-2006-5725 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 2.8% (pctl 86)

Patch early

A public exploit exists.

Description

The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which returns different HTTP status codes for existing and non-existing directories.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS2.85% — more likely to be exploited than 86% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2006-11-04
Last modified2026-06-16

Affected (1)

VendorProduct
aep networkssmartgate ssl server

Public exploits

SourceTitleDate
exploit-dbAEP SmartGate 4.3b - 'GET' Arbitrary File Download2006-10-24

References

→ the Explorer  ·  watch your stack  ·  NVD