VulnerabilityModified
CVE-2004-2323
DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server username and password, via a GET request for source or configuration files such as Web.config.
MEDIUM 5.0EPSS 1.40%
Does this matter?
Lower severity and a low EPSS score (1.40%). Track it; it rarely justifies an emergency change on its own.
Description
DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server username and password, via a GET request for source or configuration files such as Web.config.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- dnnsoftware/dotnetnuke
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-01/1161.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/10747
- http://www.osvdb.org/3749
- http://www.securityfocus.com/bid/9518Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14972
- http://archives.neohapsis.com/archives/fulldisclosure/2004-01/1161.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/10747
- http://www.osvdb.org/3749
- http://www.securityfocus.com/bid/9518Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14972
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.