VulnerabilityModified
CVE-2007-5172
Quicksilver Forums before 1.4.1 allows remote attackers to obtain sensitive information by causing unspecified connection errors, which reveals the database password in the resulting error message.
MEDIUM 5.0EPSS 1.22%
Does this matter?
Lower severity and a low EPSS score (1.22%). Track it; it rarely justifies an emergency change on its own.
Description
Quicksilver Forums before 1.4.1 allows remote attackers to obtain sensitive information by causing unspecified connection errors, which reveals the database password in the resulting error message.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- quicksilver forums/quicksilver forums
- Source
- cve@mitre.org
References
- http://forums.quicksilverforums.com/index.php?a=topic&t=1332Patch
- http://secunia.com/advisories/26998Vendor Advisory
- http://www.securityfocus.com/bid/25887
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36891
- http://forums.quicksilverforums.com/index.php?a=topic&t=1332Patch
- http://secunia.com/advisories/26998Vendor Advisory
- http://www.securityfocus.com/bid/25887
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36891
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.