6.8
CVE-2014-3006
- EPSS 1.31%
- Veröffentlicht 02.05.2014 14:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Sitepark Information Enterprise Server (IES) 2.9 before 2.9.6, when upgraded from an earlier version, does not properly restrict access, which allows remote attackers to change the manager account password and obtain sensitive information via a request to install/.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sitepark ≫ Information Enterprise Server Version2.9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.31% | 0.669 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://seclists.org/fulldisclosure/2014/Apr/317
http://www.securityfocus.com/archive/1/531986/100/0/threaded
http://www.securityfocus.com/bid/67165
https://www.lsexperts.de/advisories/lse-2014-04-10.txt