Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-5447

Опубликовано: 20 окт. 2014
Источник: nvd
CVSS2: 2.1
EPSS Низкий

Описание

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:zarafa:webapp:1.6:*:*:*:*:*:*:*
cpe:2.3:a:zarafa:zarafa:7.1.10:*:*:*:*:*:*:*

EPSS

Процентиль: 15%
0.00048
Низкий

2.1 Low

CVSS2

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 11 лет назад

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

debian
больше 11 лет назад

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644 ...

github
больше 3 лет назад

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

EPSS

Процентиль: 15%
0.00048
Низкий

2.1 Low

CVSS2

Дефекты

CWE-200