5
CVSSv2

CVE-2013-3597

Published: 28/08/2013 Updated: 05/09/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

servlet/CollectionListServlet in SearchBlox prior to 7.5 build 1 allows remote malicious users to read usernames and passwords via a getList action.

Vulnerable Product Search on Vulmon Subscribe to Product

searchblox searchblox 7.1

searchblox searchblox 7.2

searchblox searchblox 7.3

searchblox searchblox 7.4

searchblox searchblox 6.2

searchblox searchblox 6.4

searchblox searchblox 7.0

searchblox searchblox

searchblox searchblox 6.3

Exploits

source: wwwsecurityfocuscom/bid/61974/info SearchBlox is prone to multiple information-disclosure vulnerabilities Attackers can exploit these issues to obtain sensitive information that may aid in launching further attacks SearchBlox 74 Build 1 is vulnerable; other versions may also be affected wwwexamplecom/searchblox/se ...