Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2005-4880 | First vendor Publication | 2009-03-31 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4880 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-264 | Permissions, Privileges, and Access Controls |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 2 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
18572 | Jax Guestbook logfile.csv User IP Disclosure Jax Guestbook contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a direct request for the logfile.csv file occurs, which will disclose IP addresses of users resulting in a loss of confidentiality. |
18571 | Jax Guestbook ips2block Banned IP List Disclosure Jax Guestbook contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a direct request to the ips2block file occurs, which will disclose the list of banned IP addresses, resulting in a loss of confidentiality. |
18570 | Jax Guestbook guestbook_ips2block Banned IP List Disclosure Jax Guestbook contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a direct request to the guestbook_ips2block file occurs, which will disclose the list of banned IP addresses, resulting in a loss of confidentiality. |
18569 | Jax Guestbook guestbook File Client IP Disclosure Jax Guestbook contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a direct request to the guestbook file occurs, which will disclose the IP addresses of users who have posted to the guestbook, resulting in a loss of confidentiality. |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 23:11:43 |
|
2019-05-10 12:01:42 |
|
2016-04-26 14:10:29 |
|
2013-05-11 11:39:25 |
|