VulnerabilityModified
CVE-2005-4015
PHP Web Statistik 1.4 does not rotate the log database or limit the size of the referer field, which allows remote attackers to fill the log files via a large number of requests, as demonstrated using pixel.php.
MEDIUM 5.0EPSS 1.39%
Does this matter?
Lower severity and a low EPSS score (1.39%). Track it; it rarely justifies an emergency change on its own.
Description
PHP Web Statistik 1.4 does not rotate the log database or limit the size of the referer field, which allows remote attackers to fill the log files via a large number of requests, as demonstrated using pixel.php.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.39% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- php web/statistik
- Source
- cve@mitre.org
References
- http://cert.uni-stuttgart.de/archive/bugtraq/2005/11/msg00325.htmlVendor Advisory
- http://freewebstat.com/changelog-english.html
- http://securityreason.com/securityalert/214
- http://www.ush.it/2005/11/19/php-web-statistik/Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23386
- http://cert.uni-stuttgart.de/archive/bugtraq/2005/11/msg00325.htmlVendor Advisory
- http://freewebstat.com/changelog-english.html
- http://securityreason.com/securityalert/214
- http://www.ush.it/2005/11/19/php-web-statistik/Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23386
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.