VulnerabilityModified
CVE-2006-0370
Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes.
MEDIUM 5.0EPSS 1.76%
Does this matter?
Lower severity and a low EPSS score (1.76%). Track it; it rarely justifies an emergency change on its own.
Description
Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.76% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- noah medling/rcblog
- Source
- cve@mitre.org
References
- http://evuln.com/vulns/42/summary.htmlExploit, Vendor Advisory
- http://secunia.com/advisories/18547Vendor Advisory
- http://securitytracker.com/id?1015523
- http://www.fluffington.com/index.php?page=rcblogURL Repurposed
- http://www.osvdb.org/22679
- http://www.securityfocus.com/archive/1/422499/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24249
- http://evuln.com/vulns/42/summary.htmlExploit, Vendor Advisory
- http://secunia.com/advisories/18547Vendor Advisory
- http://securitytracker.com/id?1015523
- http://www.fluffington.com/index.php?page=rcblogURL Repurposed
- http://www.osvdb.org/22679
- http://www.securityfocus.com/archive/1/422499/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24249
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.