CVE-2005-1783
BookReview beta 1.0 allows remote attackers to obtain the path of the web server via certain parameters to search.htm, possibly due to a search[string] parameter with a missing value or an incorrect submit[type] value, which reveals the path in the…
Does this matter?
Lower severity and a low EPSS score (1.55%). Track it; it rarely justifies an emergency change on its own.
Description
BookReview beta 1.0 allows remote attackers to obtain the path of the web server via certain parameters to search.htm, possibly due to a search[string] parameter with a missing value or an incorrect submit[type] value, which reveals the path in the resulting error message. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.55% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- w.m.r. simpson/bookreview
- Source
- cve@mitre.org
References
- http://lostmon.blogspot.com/2005/05/bookreview-10-multiple-variable-xss.htmlExploit, Vendor Advisory
- http://secunia.com/advisories/1014058
- http://www.osvdb.org/16880
- http://www.osvdb.org/16881Exploit, Vendor Advisory
- http://lostmon.blogspot.com/2005/05/bookreview-10-multiple-variable-xss.htmlExploit, Vendor Advisory
- http://secunia.com/advisories/1014058
- http://www.osvdb.org/16880
- http://www.osvdb.org/16881Exploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.