5
CVSSv2

CVE-2012-4976

Published: 12/12/2012 Updated: 12/12/2012
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

selectawasset.asp in Layton Helpbox 4.4.0 allows remote malicious users to discover ODBC database credentials via an element=sys_asset_id request, which is not properly handled during construction of an error page.

Vulnerable Product Search on Vulmon Subscribe to Product

layton technology helpbox 4.4.0

Exploits

Layton Helpbox version 440 discloses login and password information for the database in an error page ...