7.8
CVSSv2

CVE-2009-1949

Published: 05/06/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

import_wbb1.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote malicious users to obtain sensitive information via a direct request, which reveals the installation path in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

unclassified newsboard 1.6.4

Exploits

# Author_ girex # Homepage_ girexaltervistaorg # Date_ 31/05/2009 # CMS_ Unclassified NewsBoard 164 (and maybe lower) # Dork_ "This board is powered by the Unclassified NewsBoard software, 164" # Multiple remote vulnerabilities # 1) Remote SQL Injection (phpini regardless) # 2) Logs File Disclosure (register_globals = On) # 3) ...