VulnerabilityModified
CVE-2003-1404
DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information such as SQL usernames and passwords.
HIGH 7.5EPSS 1.36%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information such as SQL usernames and passwords.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.36% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- dotbr/botbr
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0070.html
- http://www.osvdb.org/5092
- http://www.securityfocus.com/bid/6865
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11354
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0070.html
- http://www.osvdb.org/5092
- http://www.securityfocus.com/bid/6865
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11354
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.