Lucene search

K
cveMitreCVE-2005-0853
HistoryMay 02, 2005 - 4:00 a.m.

CVE-2005-0853

2005-05-0204:00:00
mitre
web.nvd.nist.gov
22
betaparticle
bp blog
database storage
remote attackers
sensitive information
cve-2005-0853
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.017

Percentile

87.7%

betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request to (1) dbBlogMX.mdb for versions before 3.0, or (2) Blog.mdb for versions 3.0 and later. NOTE: it was later reported that vector 2 also affects versions 6.0 through 9.0.

Affected configurations

Nvd
Node
betaparticlebetaparticle_blogMatch2.0
OR
betaparticlebetaparticle_blogMatch3.0
VendorProductVersionCPE
betaparticlebetaparticle_blog2.0cpe:2.3:a:betaparticle:betaparticle_blog:2.0:*:*:*:*:*:*:*
betaparticlebetaparticle_blog3.0cpe:2.3:a:betaparticle:betaparticle_blog:3.0:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.017

Percentile

87.7%

Related for CVE-2005-0853