CVE-2012-0263
Estado: ModificadaMedia (4)—
monitor/index.php in op5 Monitor and op5 Appliance before 5.5.1 allows remote authenticated users to obtain sensitive information such as database and user credentials via error messages that are triggered by (1) a malformed hoststatustypes parameter to status/service/all or (2) a crafted request to config.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N
- Puntuación base: 4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.94%
- Percentil entre todas las CVEs puntuadas: 79
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200
Referencias
- http://seclists.org/fulldisclosure/2012/Jan/62
- http://secunia.com/advisories/47344
- http://www.ekelow.se/file_uploads/Advisories/ekelow-aid-2012-01.pdf
- http://www.op5.com/news/support-news/fixed-vulnerabilities-op5-monitor-op5-appliance/
- http://www.osvdb.org/78067
- https://bugs.op5.com/view.php?id=5094
- http://seclists.org/fulldisclosure/2012/Jan/62
- http://secunia.com/advisories/47344
- http://www.ekelow.se/file_uploads/Advisories/ekelow-aid-2012-01.pdf
- http://www.op5.com/news/support-news/fixed-vulnerabilities-op5-monitor-op5-appliance/
- http://www.osvdb.org/78067
- https://bugs.op5.com/view.php?id=5094
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-0263",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2013-12-31T20:55:15.073",
"references": [
{
"url": "http://seclists.org/fulldisclosure/2012/Jan/62",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/47344",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.ekelow.se/file_uploads/Advisories/ekelow-aid-2012-01.pdf",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.op5.com/news/support-news/fixed-vulnerabilities-op5-monitor-op5-appliance/",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/78067",
"source": "cve@mitre.org"
},
{
"url": "https://bugs.op5.com/view.php?id=5094",
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2012/Jan/62",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/47344",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ekelow.se/file_uploads/Advisories/ekelow-aid-2012-01.pdf",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.op5.com/news/support-news/fixed-vulnerabilities-op5-monitor-op5-appliance/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/78067",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugs.op5.com/view.php?id=5094",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "monitor/index.php in op5 Monitor and op5 Appliance before 5.5.1 allows remote authenticated users to obtain sensitive information such as database and user credentials via error messages that are triggered by (1) a malformed hoststatustypes parameter to status/service/all or (2) a crafted request to config."
},
{
"lang": "es",
"value": "monitor / index.php en el Monitor y Appliance de op5 anteriores a 5.5.1 permite a usuarios remotos autenticados obtener información confidencial, como bases de datos y las credenciales del usuario a través de los mensajes de error que se desencadenan por (1) un parámetro hoststatustypes malformado en estado/servicio/ todos o (2) una solicitud manipulada en las configuraciones."
}
],
"lastModified": "2026-06-16T23:37:00.677",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:op5:monitor:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B57AA6A1-CF28-46DC-80FA-67F1023933EF",
"versionEndIncluding": "5.5.0"
},
{
"criteria": "cpe:2.3:a:op5:monitor:5.3.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5249E2B6-4B2B-4A4D-9C39-8362B422B0E5"
},
{
"criteria": "cpe:2.3:a:op5:monitor:5.4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "108F8953-B90D-4341-8AD5-39E94F7F320B"
},
{
"criteria": "cpe:2.3:a:op5:monitor:5.4.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "14C73510-4999-4C96-9705-59274F97BA77"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}