5
CVE-2005-4013
- EPSS 1.62%
- Veröffentlicht 05.12.2005 11:03:00
- Zuletzt bearbeitet 16.06.2026 22:18:03
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
PHP Web Statistik 1.4 stores the stat.cfg file under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as statistics and the log directory location, possibly including the logdb.dta file.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.62% | 0.729 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://cert.uni-stuttgart.de/archive/bugtraq/2005/11/msg00325.html
http://freewebstat.com/changelog-english.html
http://secunia.com/advisories/17789
http://www.ush.it/2005/11/19/php-web-statistik/
http://www.vupen.com/english/advisories/2005/2645
http://www.osvdb.org/21209
http://www.osvdb.org/21210
https://exchange.xforce.ibmcloud.com/vulnerabilities/23382