VulnerabilityModified
CVE-2008-5592
Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users-zza21.mdb.
MEDIUM 5.0EPSS 2.61%
Does this matter?
Lower severity and a low EPSS score (2.61%). Track it; it rarely justifies an emergency change on its own.
Description
Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users-zza21.mdb.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.61% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- iwrite/nightfall personal diary
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/33011Vendor Advisory
- http://securityreason.com/securityalert/4742
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47111
- https://www.exploit-db.com/exploits/7351
- http://secunia.com/advisories/33011Vendor Advisory
- http://securityreason.com/securityalert/4742
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47111
- https://www.exploit-db.com/exploits/7351
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.