5

CVE-2005-4013

PHP Web Statistik 1.4 stores the stat.cfg file under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as statistics and the log directory location, possibly including the logdb.dta file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php WebStatistik Version1.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.62% 0.729
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://cert.uni-stuttgart.de/archive/bugtraq/2005/11/msg00325.html
Vendor Advisory
http://freewebstat.com/changelog-english.html
http://secunia.com/advisories/17789
Vendor Advisory
http://www.ush.it/2005/11/19/php-web-statistik/
Patch
Vendor Advisory
http://www.vupen.com/english/advisories/2005/2645
http://www.osvdb.org/21209
http://www.osvdb.org/21210
https://exchange.xforce.ibmcloud.com/vulnerabilities/23382