Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r8xv-6hx2-jxhm

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.

Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.

EPSS

Процентиль: 83%
0.01983
Низкий

Связанные уязвимости

nvd
почти 17 лет назад

Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.

EPSS

Процентиль: 83%
0.01983
Низкий