VulnerabilityModified
CVE-2003-1173
Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the search option checkboxes and leaving the text field blank, which will return all files in the searched…
MEDIUM 5.0EPSS 3.41%
Does this matter?
Lower severity and a low EPSS score (3.41%). Track it; it rarely justifies an emergency change on its own.
Description
Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the search option checkboxes and leaving the text field blank, which will return all files in the searched directory.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 3.41% probability · 88th percentile
- CISA KEV
- Not listed
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/10084Exploit, Patch
- http://www.osvdb.org/2723
- http://www.securityfocus.com/archive/1/342765Exploit
- http://www.securityfocus.com/archive/1/342909
- http://www.securityfocus.com/bid/8920Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13546
- http://secunia.com/advisories/10084Exploit, Patch
- http://www.osvdb.org/2723
- http://www.securityfocus.com/archive/1/342765Exploit
- http://www.securityfocus.com/archive/1/342909
- http://www.securityfocus.com/bid/8920Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/13546
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.