7.5
CVE-2006-1164
- EPSS 2.66%
- Veröffentlicht 12.03.2006 21:02:00
- Zuletzt bearbeitet 16.06.2026 22:22:08
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Nodez 4.6.1.1 and earlier stores sensitive data in the list.gtdat file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password hashes by directly accessing list.gtdat.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.66% | 0.837 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://hamid.ir/security/nodez.txt
http://www.securityfocus.com/bid/17066
http://www.osvdb.org/23775