5.3
CVSSv3

CVE-2014-10079

Published: 23/02/2019 Updated: 18/03/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed because of incorrect processing of an index.php/ trailing slash.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vembu storegrid 4.4

Exploits

# Exploit Title: Vembu Storegrid Web Interface 440 - Multiple Vulnerabilities # Discovery Date: 2018-12-05 # Exploit Author: Gionathan "John" Reale # Vendor Homepage: wwwvembucom/ # Software Link : N/A # Google Dork: N/A # Version: 440 # CVE : CVE-2014-10078,CVE-2014-10079 Description StoreGrid enables you to offer an automated o ...
Vembu Storegrid Web Interface version 440 suffers from cross site scripting and information leakage vulnerabilities ...