VulnerabilityModified
CVE-2005-0938
Ublog Reload 1.0 through 1.0.4 stores ublogreload.mdb under the web root, which allows remote attackers to read usernames and hashed passwords via a direct request to ublogreload.mdb.
MEDIUM 5.0EPSS 1.39%
Does this matter?
Lower severity and a low EPSS score (1.39%). Track it; it rarely justifies an emergency change on its own.
Description
Ublog Reload 1.0 through 1.0.4 stores ublogreload.mdb under the web root, which allows remote attackers to read usernames and hashed passwords via a direct request to ublogreload.mdb.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.39% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- uapplication/ublog reload
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=111214393101387&w=2
- http://secunia.com/advisories/14725
- http://securitytracker.com/id?1013603
- http://www.persianhacker.net/news/news-2945.html
- http://marc.info/?l=bugtraq&m=111214393101387&w=2
- http://secunia.com/advisories/14725
- http://securitytracker.com/id?1013603
- http://www.persianhacker.net/news/news-2945.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.