VulnerabilityModified
CVE-2005-2600
FUDForum 2.6.15 with "Tree View" enabled, as used in other products such as phpgroupware and egroupware, allows remote attackers to read private posts via a modified mid parameter.
MEDIUM 5.0EPSS 1.60%
Does this matter?
Lower severity and a low EPSS score (1.60%). Track it; it rarely justifies an emergency change on its own.
Description
FUDForum 2.6.15 with "Tree View" enabled, as used in other products such as phpgroupware and egroupware, allows remote attackers to read private posts via a modified mid parameter.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.60% probability · 74th percentile
- CISA KEV
- Not listed
- Affected
- ilia alshanetsky/fudforum
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2005-08/0383.htmlPatch
- http://secunia.com/advisories/16414Patch, Vendor Advisory
- http://secunia.com/advisories/17643
- http://www.debian.org/security/2005/dsa-798
- http://www.debian.org/security/2005/dsa-899
- http://www.securityfocus.com/bid/14556
- http://archives.neohapsis.com/archives/fulldisclosure/2005-08/0383.htmlPatch
- http://secunia.com/advisories/16414Patch, Vendor Advisory
- http://secunia.com/advisories/17643
- http://www.debian.org/security/2005/dsa-798
- http://www.debian.org/security/2005/dsa-899
- http://www.securityfocus.com/bid/14556
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.