CVE-2008-3728
Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to determine the installation path, IP addresses, and error…
Does this matter?
Lower severity and a low EPSS score (1.57%). Track it; it rarely justifies an emergency change on its own.
Description
Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to determine the installation path, IP addresses, and error messages via direct requests to files under LOG/.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- microworld technologies/mailscan
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=121881329424635&w=2Exploit
- http://secunia.com/advisories/31534Vendor Advisory
- http://securityreason.com/securityalert/4172
- http://www.oliverkarow.de/research/mailscan.txtExploit
- http://www.securityfocus.com/bid/30700Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44518
- http://marc.info/?l=bugtraq&m=121881329424635&w=2Exploit
- http://secunia.com/advisories/31534Vendor Advisory
- http://securityreason.com/securityalert/4172
- http://www.oliverkarow.de/research/mailscan.txtExploit
- http://www.securityfocus.com/bid/30700Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44518
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.