Lucene search

K
nvd[email protected]NVD:CVE-2004-2060
HistoryDec 31, 2004 - 5:00 a.m.

CVE-2004-2060

2004-12-3105:00:00
web.nvd.nist.gov
3

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.013

Percentile

85.7%

ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.

Affected configurations

Nvd
Node
xlinesoftasprunnerMatch1.0
OR
xlinesoftasprunnerMatch2.0
OR
xlinesoftasprunnerMatch2.1
OR
xlinesoftasprunnerMatch2.2
OR
xlinesoftasprunnerMatch2.3
OR
xlinesoftasprunnerMatch2.4
VendorProductVersionCPE
xlinesoftasprunner1.0cpe:2.3:a:xlinesoft:asprunner:1.0:*:*:*:*:*:*:*
xlinesoftasprunner2.0cpe:2.3:a:xlinesoft:asprunner:2.0:*:*:*:*:*:*:*
xlinesoftasprunner2.1cpe:2.3:a:xlinesoft:asprunner:2.1:*:*:*:*:*:*:*
xlinesoftasprunner2.2cpe:2.3:a:xlinesoft:asprunner:2.2:*:*:*:*:*:*:*
xlinesoftasprunner2.3cpe:2.3:a:xlinesoft:asprunner:2.3:*:*:*:*:*:*:*
xlinesoftasprunner2.4cpe:2.3:a:xlinesoft:asprunner:2.4:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.013

Percentile

85.7%

Related for NVD:CVE-2004-2060