7.5
CVSSv2

CVE-2006-1164

Published: 12/03/2006 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Nodez 4.6.1.1 and previous versions stores sensitive data in the list.gtdat file under the web document root with insufficient access control, which allows remote malicious users to obtain usernames and password hashes by directly accessing list.gtdat.

Vulnerable Product Search on Vulmon Subscribe to Product

nodez nodez 4.6.1.1

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? echo "Nodez 4611 Mercury (possibly prior versions) multiple vulnerabilities\r\n"; echo "by rgod rgod@autisticiorg\r\n"; echo "site: retrogodaltervistaorg\r\n\r\n"; /* software: site: nodezgreentintedcom/ description: Nodez - "An open source (content management system), designed ...