5
CVE-2008-3060
- EPSS 1.22%
- Veröffentlicht 08.10.2008 00:00:04
- Zuletzt bearbeitet 16.06.2026 22:55:00
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php) and (2) an invalid session ID, which reveals the installation path in an error message.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.22% | 0.647 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
http://osvdb.org/ref/48/48-v-webmail.txt
http://www.osvdb.org/48793
http://www.osvdb.org/48794
https://exchange.xforce.ibmcloud.com/vulnerabilities/45853