VulnerabilityModified
CVE-2004-2060
ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.
MEDIUM 5.0EPSS 7.94%
Does this matter?
Lower severity and a low EPSS score (7.94%). Track it; it rarely justifies an emergency change on its own.
Description
ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 7.94% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- xlinesoft/asprunner
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0011.htmlExploit
- http://ferruh.mavituna.com/article/?574Exploit
- http://marc.info/?l=bugtraq&m=109086977330418&w=2
- http://secunia.com/advisories/12164
- http://securitytracker.com/id?1010777
- http://www.osvdb.org/8253
- http://www.securityfocus.com/bid/10799
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16802
- http://archives.neohapsis.com/archives/vulnwatch/2004-q3/0011.htmlExploit
- http://ferruh.mavituna.com/article/?574Exploit
- http://marc.info/?l=bugtraq&m=109086977330418&w=2
- http://secunia.com/advisories/12164
- http://securitytracker.com/id?1010777
- http://www.osvdb.org/8253
- http://www.securityfocus.com/bid/10799
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16802
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.