CVE-2014-10079 Information
Feb 14, 2021
cve
Description
In Vembu StoreGrid 4.4.x the front page of the server web interface leaks the private IP address in the \ipaddress\ hidden form value of the HTML source code which is disclosed because of incorrect processing of an index.php/ trailing slash.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://cxsecurity.com/issue/WLB-2018120091 https://packetstormsecurity.com/files/127786/Vembu-Backup-Disaster-Recovery-6.1-Follow-Up.html https://seclists.org/fulldisclosure/2014/Aug/8 https://www.exploit-db.com/exploits/46549/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: