VulnerabilityModified
CVE-2006-1718
Magus Perde Clever Copy 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to view the database username and password via a direct request for connect.inc.
MEDIUM 5.0EPSS 7.39%
Does this matter?
Lower severity and a low EPSS score (7.39%). Track it; it rarely justifies an emergency change on its own.
Description
Magus Perde Clever Copy 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to view the database username and password via a direct request for connect.inc.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 7.39% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- clever copy/clever copy
- Source
- cve@mitre.org
References
- http://advisories.echo.or.id/adv/adv28-K-159-2006.txtExploit, Vendor Advisory
- http://secunia.com/advisories/19579Exploit, Vendor Advisory
- http://www.securityfocus.com/archive/1/430369/100/0/threaded
- http://www.securityfocus.com/bid/17461Exploit
- http://www.vupen.com/english/advisories/2006/1316
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25720
- http://advisories.echo.or.id/adv/adv28-K-159-2006.txtExploit, Vendor Advisory
- http://secunia.com/advisories/19579Exploit, Vendor Advisory
- http://www.securityfocus.com/archive/1/430369/100/0/threaded
- http://www.securityfocus.com/bid/17461Exploit
- http://www.vupen.com/english/advisories/2006/1316
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25720
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.