Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-5447

Опубликовано: 20 окт. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 2.1

Описание

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

lucid

ignored

end of life, was needs-triage
precise

DNE

trusty

DNE

trusty/esm

DNE

upstream

needs-triage

utopic

DNE

vivid

DNE

Показывать по

EPSS

Процентиль: 15%
0.00048
Низкий

2.1 Low

CVSS2

Связанные уязвимости

nvd
больше 11 лет назад

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

debian
больше 11 лет назад

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644 ...

github
больше 3 лет назад

Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

EPSS

Процентиль: 15%
0.00048
Низкий

2.1 Low

CVSS2