VulnerabilityModified
CVE-2004-1103
MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to gain sensitive information via the debug parameter, which reveals information such as the path to the web root and the web server version.
MEDIUM 5.0EPSS 2.76%
Does this matter?
Lower severity and a low EPSS score (2.76%). Track it; it rarely justifies an emergency change on its own.
Description
MailPost 5.1.1sv, and possibly earlier versions, when debug mode is enabled, allows remote attackers to gain sensitive information via the debug parameter, which reveals information such as the path to the web root and the web server version.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.76% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- tips/mailpost
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/858726Third Party Advisory, US Government Resource
- http://www.procheckup.com/security_info/vuln_pr0409.html
- http://www.securityfocus.com/bid/11595Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17952
- http://www.kb.cert.org/vuls/id/858726Third Party Advisory, US Government Resource
- http://www.procheckup.com/security_info/vuln_pr0409.html
- http://www.securityfocus.com/bid/11595Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17952
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.