« Volver al listado

CVE-2003-1571

Estado: ModificadaMedia (5)—

Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for database/WWGguestbook.mdb. NOTE: it was later reported that 8.21 is also affected.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2003-1571",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-04-02T15:30:00.233",
  "references": [
    {
      "url": "http://secunia.com/advisories/9639",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=25863",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/2492",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/7488",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/9639",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=25863",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/2492",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/7488",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for database/WWGguestbook.mdb.  NOTE: it was later reported that 8.21 is also affected."
    },
    {
      "lang": "es",
      "value": "Web Wiz Guestbook v6.0 guarda información sensible bajo la raíz de la web con insuficientes controles de acceso, lo que permite a atacantes remotos descargar la base de datos y obtener información sensible a través de una petición directa para database/WWGguestbook.mdb. NOTA: Se reportó mas tarde que la v8.21 también esta afectada."
    }
  ],
  "lastModified": "2026-06-16T22:04:40.817",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:webwizguide:web_wiz_guestbook:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A47E3ED9-2146-40A3-A728-3794F8377470"
            },
            {
              "criteria": "cpe:2.3:a:webwizguide:web_wiz_guestbook:8.21:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E319FAC-3248-46F1-8862-A965E0E8FE66"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}