5
CVE-2007-5172
- EPSS 1.22%
- Veröffentlicht 01.10.2007 20:17:00
- Zuletzt bearbeitet 16.06.2026 22:45:35
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Quicksilver Forums before 1.4.1 allows remote attackers to obtain sensitive information by causing unspecified connection errors, which reveals the database password in the resulting error message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Quicksilver Forums ≫ Quicksilver Forums Version <= 1.4.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.22% | 0.647 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://forums.quicksilverforums.com/index.php?a=topic&t=1332
http://secunia.com/advisories/26998
http://www.securityfocus.com/bid/25887
https://exchange.xforce.ibmcloud.com/vulnerabilities/36891