Lucene search

K
cveMitreCVE-2012-6313
HistoryDec 11, 2012 - 12:18 p.m.

CVE-2012-6313

2012-12-1112:18:37
CWE-200
mitre
web.nvd.nist.gov
34
cve
2012
6313
simple gmail login
wordpress
plugin
information disclosure
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.008

Percentile

81.4%

simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a request that lacks a timezone, leading to disclosure of the installation path in a stack trace.

Affected configurations

Nvd
Node
simple_gmail_login1.1.2
OR
simple_gmail_login1.1.3
AND
wordpresswordpressMatch-
VendorProductVersionCPE
simple_gmail_login1.1.2*cpe:2.3:a:simple_gmail_login:1.1.2:*:*:*:*:*:*:*:*
simple_gmail_login1.1.3*cpe:2.3:a:simple_gmail_login:1.1.3:*:*:*:*:*:*:*:*
wordpresswordpress-cpe:2.3:a:wordpress:wordpress:-:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.008

Percentile

81.4%