5

CVE-2007-2684

Exploit
Jetbox CMS 2.1 allows remote attackers to obtain sensitive information via (1) a direct request to (a) main_page.php, (b) open_tree.php, and (c) outputs.php; (2) a malformed view parameter to index.php, as demonstrated with an SQL injection manipulation; or (3) the id[] parameter to admin/cms/opentree.php, which reveals the installation path in the resulting error message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JetboxJetbox Cms Version2.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.61% 0.728
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=full-disclosure&m=117974375029054&w=2
Vendor Advisory
Exploit
http://osvdb.org/34787
http://osvdb.org/34788
http://osvdb.org/34789
http://osvdb.org/34790
http://www.netvigilance.com/advisory0027
Vendor Advisory
Exploit
http://www.osvdb.org/34783
http://www.securityfocus.com/archive/1/469222/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/34385