CVE-2005-1586
Quick.Forum 2.1.6 stores potentially sensitive information such as usernames, banned IP addresses, censored words, and backups under the web document root, which allows remote attackers to obtain that information via a direct request to (1)…
Does this matter?
Lower severity and a low EPSS score (1.39%). Track it; it rarely justifies an emergency change on its own.
Description
Quick.Forum 2.1.6 stores potentially sensitive information such as usernames, banned IP addresses, censored words, and backups under the web document root, which allows remote attackers to obtain that information via a direct request to (1) db/users.txt, (2) db/banList.txt, (3) db/censureWords.txt, or (4) backup files.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.39% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- open solution/quick.forum
- Source
- cve@mitre.org
References
- http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.htmlVendor Advisory
- http://secunia.com/advisories/15200Vendor Advisory
- http://www.osvdb.org/16328Vendor Advisory
- http://www.osvdb.org/16329Vendor Advisory
- http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.htmlVendor Advisory
- http://secunia.com/advisories/15200Vendor Advisory
- http://www.osvdb.org/16328Vendor Advisory
- http://www.osvdb.org/16329Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.