Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-0543

Опубликовано: 29 янв. 2007
Источник: nvd
CVSS2: 9.4
EPSS Низкий

Описание

ZixForum 1.14 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for Zixforum.mdb. NOTE: a followup post suggests that this issue only occurs if the administrator does not properly follow installation directions.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zixforum:zixforum:*:*:*:*:*:*:*:*
Версия до 1.14 (включая)

EPSS

Процентиль: 54%
0.00318
Низкий

9.4 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

ZixForum 1.14 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for Zixforum.mdb. NOTE: a followup post suggests that this issue only occurs if the administrator does not properly follow installation directions.

EPSS

Процентиль: 54%
0.00318
Низкий

9.4 Critical

CVSS2

Дефекты

NVD-CWE-Other