7.5
CVE-2019-11633
- EPSS 0.29%
- Veröffentlicht 01.05.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:29
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
HoneyPress through 2016-09-27 can be fingerprinted by attackers because of the ingrained unique www.atxsec.com and ayylmao.wpengine.com hostnames within the fake WordPress templates. This allows attackers to discover and avoid this honeypot system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Honeypress Project ≫ Honeypress SwPlatformwordpress Version <= 2016-09-27
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.515 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.