VulnerabilityModified
CVE-2005-1055
TowerBlog 0.6 and earlier stores the login data file under the web root, which allows remote attackers to obtain the MD5 checksums of the username and password via a direct request to the _dat/login file.
HIGH 7.5EPSS 1.59%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
TowerBlog 0.6 and earlier stores the login data file under the web root, which allows remote attackers to obtain the MD5 checksums of the username and password via a direct request to the _dat/login file.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.59% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- towerblog/towerblog
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=111323802003019&w=2
- http://secunia.com/advisories/14884Vendor Advisory
- http://securitytracker.com/id?1013675Patch, Vendor Advisory
- http://www.osvdb.org/15425
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20039
- http://marc.info/?l=bugtraq&m=111323802003019&w=2
- http://secunia.com/advisories/14884Vendor Advisory
- http://securitytracker.com/id?1013675Patch, Vendor Advisory
- http://www.osvdb.org/15425
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20039
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.