VulnerabilityModified
CVE-2004-2196
Zanfi CMS lite 1.1 allows remote attackers to obtain the full path of the web server via direct requests without required arguments to (1) adm_pages.php, (2) corr_pages.php, (3) del_block.php, (4) del_page.php, (5) footer.php, (6) home.php, and others.
MEDIUM 5.0EPSS 2.31%
Does this matter?
Lower severity and a low EPSS score (2.31%). Track it; it rarely justifies an emergency change on its own.
Description
Zanfi CMS lite 1.1 allows remote attackers to obtain the full path of the web server via direct requests without required arguments to (1) adm_pages.php, (2) corr_pages.php, (3) del_block.php, (4) del_page.php, (5) footer.php, (6) home.php, and others.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.31% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- zanfi solutions/zanfi cms lite
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/12792Vendor Advisory
- http://securitytracker.com/id?1011612
- http://www.osvdb.org/10677
- http://www.osvdb.org/10678
- http://www.osvdb.org/10679
- http://www.osvdb.org/10680
- http://www.osvdb.org/10681
- http://www.osvdb.org/10682
- http://www.securityfocus.com/archive/1/378053Exploit, Vendor Advisory
- http://www.zanfi.nl/index1.php?flag=cmslite
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17687
- http://secunia.com/advisories/12792Vendor Advisory
- http://securitytracker.com/id?1011612
- http://www.osvdb.org/10677
- http://www.osvdb.org/10678
- http://www.osvdb.org/10679
- http://www.osvdb.org/10680
- http://www.osvdb.org/10681
- http://www.osvdb.org/10682
- http://www.securityfocus.com/archive/1/378053Exploit, Vendor Advisory
- http://www.zanfi.nl/index1.php?flag=cmslite
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17687
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.