Lucene search

K
cveJpcertCVE-2010-3925
HistoryJan 13, 2011 - 7:00 p.m.

CVE-2010-3925

2011-01-1319:00:02
CWE-255
jpcert
web.nvd.nist.gov
22
contents-mall
security vulnerability
administrative password
remote attackers
sensitive information
data modification

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.006

Percentile

77.6%

Contents-Mall before 15 does not properly handle passwords, which allows remote attackers to discover the administrative password, and consequently obtain sensitive information or modify data, via unspecified vectors.

Affected configurations

Nvd
Node
wb-icontents-mallRange14.00
VendorProductVersionCPE
wb-icontents-mall*cpe:2.3:a:wb-i:contents-mall:*:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.006

Percentile

77.6%

Related for CVE-2010-3925