Lucene search

K
cvelistMitreCVELIST:CVE-2005-4880
HistoryOct 03, 2022 - 4:22 p.m.

CVE-2005-4880

2022-10-0316:22:44
mitre
www.cve.org
jax guestbook
sensitive information
web root
remote attackers
information disclosure

6.2 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

74.3%

Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.

6.2 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

74.3%

Related for CVELIST:CVE-2005-4880