VulnerabilityModified
CVE-2008-5218
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords.
MEDIUM 5.0EPSS 2.70%
Does this matter?
Lower severity and a low EPSS score (2.70%). Track it; it rarely justifies an emergency change on its own.
Description
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext passwords.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.70% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- scriptsez/freeze greetings
- Source
- cve@mitre.org
References
- http://osvdb.org/49883
- http://secunia.com/advisories/32744Vendor Advisory
- http://securityreason.com/securityalert/4633
- http://www.securityfocus.com/bid/32325
- https://www.exploit-db.com/exploits/7140
- http://osvdb.org/49883
- http://secunia.com/advisories/32744Vendor Advisory
- http://securityreason.com/securityalert/4633
- http://www.securityfocus.com/bid/32325
- https://www.exploit-db.com/exploits/7140
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.