SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-2060

ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.

MEDIUM 5.0EPSS 7.94%

Does this matter?

Lower severity and a low EPSS score (7.94%). Track it; it rarely justifies an emergency change on its own.

Description

ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
7.94% probability · 94th percentile
CISA KEV
Not listed
Affected
xlinesoft/asprunner
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.