CVE-2004-0665 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 2.9% (pctl 87)
Patch early
A public exploit exists.
Description
csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the web server in an error message.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 2.94% — more likely to be exploited than 87% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-08-06 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| cgiscript.net | csfaq |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | CGIScript.net CSFAQ 1.0 Script - Full Path Disclosure | 2004-06-28 |
References
- http://marc.info/?l=bugtraq&m=108844203121238&w=2
- http://www.securityfocus.com/bid/10618
- http://www.swp-zone.org/archivos/advisory-08.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16526
- http://marc.info/?l=bugtraq&m=108844203121238&w=2
- http://www.securityfocus.com/bid/10618
- http://www.swp-zone.org/archivos/advisory-08.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16526
→ the Explorer · watch your stack · NVD