4.3
CVSSv2

CVE-2003-1553

Published: 31/12/2003 Updated: 19/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote malicious users to obtain password and other user information via a direct request to a user-specific configuration directory.

Vulnerable Product Search on Vulmon Subscribe to Product

sips sips 0.2.2

Exploits

source: wwwsecurityfocuscom/bid/7134/info It has been reported that authentication is not required to view user account information As a result, an unauthorized remote attacker may be able to view potentially sensitive information This may aid in launching further attacks against a target user or system wwwexamplecom/[sips_di ...