5

CVE-2005-2053

Exploit
Just another flat file (JAF) CMS before 3.0 Final allows remote attackers to obtain sensitive information via (1) an * (asterisk) in the id parameter, (2) a blank id parameter, or (3) an * (asterisk) in the disp parameter to index.php, which reveals the path in an error message.  NOTE: a followup suggests that this may be a directory traversal or file inclusion vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Salims SofthouseJaf Cms Version1.0 Updatefinal
Salims SofthouseJaf Cms Version1.5
Salims SofthouseJaf Cms Version2.0 Updatebeta
Salims SofthouseJaf Cms Version2.0 Updatefinal
Salims SofthouseJaf Cms Version2.0.5
Salims SofthouseJaf Cms Version2.1.0
Salims SofthouseJaf Cms Version2.5
Salims SofthouseJaf Cms Version3.0 Updaterc
Salims SofthouseJaf Cms Version3.0 Updaterc_fixed
Salims SofthouseJaf Cms Version3.0 Updaterc2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.513
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.