7 High
AI Score
Confidence
Low
0.011 Low
EPSS
Percentile
84.7%
CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin name and MD5 password hash via a direct request for base/usr/0.php.
secunia.com/advisories/26805
securityreason.com/securityalert/3147
www.securityfocus.com/archive/1/479194/100/0/threaded
www.securityfocus.com/bid/25652
exchange.xforce.ibmcloud.com/vulnerabilities/36587