VulnerabilityModified
CVE-2006-1412
TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a direct request to admin/passwd.
MEDIUM 5.0EPSS 3.55%
Does this matter?
Lower severity and a low EPSS score (3.55%). Track it; it rarely justifies an emergency change on its own.
Description
TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a direct request to admin/passwd.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 3.55% probability · 89th percentile
- CISA KEV
- Not listed
- Affected
- tft gallery/tft gallery
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/19411Vendor Advisory
- http://www.securityfocus.com/archive/1/453471/100/0/threaded
- http://www.securityfocus.com/archive/1/453485/100/0/threaded
- http://www.securityfocus.com/bid/17250
- http://www.vupen.com/english/advisories/2006/1115
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25465
- https://www.exploit-db.com/exploits/1611
- http://secunia.com/advisories/19411Vendor Advisory
- http://www.securityfocus.com/archive/1/453471/100/0/threaded
- http://www.securityfocus.com/archive/1/453485/100/0/threaded
- http://www.securityfocus.com/bid/17250
- http://www.vupen.com/english/advisories/2006/1115
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25465
- https://www.exploit-db.com/exploits/1611
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.