5
CVE-2008-6528
- EPSS 3.34%
- Veröffentlicht 26.03.2009 14:30:00
- Zuletzt bearbeitet 16.06.2026 23:02:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to the URL, which accesses the alternate data stream.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.34% | 0.871 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://secunia.com/advisories/33123
http://www.securityfocus.com/archive/1/499235/100/0/threaded
http://www.securityfocus.com/archive/1/499236/100/0/threaded
http://www.securityfocus.com/bid/32804
https://exchange.xforce.ibmcloud.com/vulnerabilities/47303
https://www.exploit-db.com/exploits/7442