5
CVSSv2

CVE-2008-7118

Published: 28/08/2009 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote malicious users to obtain SQL query logs via a direct request for logs/cron.log.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

webidsupport webid 0.5.4

Exploits

|| || | || o_,_7 _|| _o_7 _|| 4_|_|| o_w_, ( : / (_) / ( ================================ ========================== ==================== |-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- ...