peter bassill · operator
$ cve CVE-2004-0665 JSON

CVE-2004-0665 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 2.9% (pctl 87)

Patch early

A public exploit exists.

Description

csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the web server in an error message.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS2.94% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploityes
Published2004-08-06
Last modified2026-06-16

Affected (1)

VendorProduct
cgiscript.netcsfaq

Public exploits

SourceTitleDate
exploit-dbCGIScript.net CSFAQ 1.0 Script - Full Path Disclosure2004-06-28

References

→ the Explorer  ·  watch your stack  ·  NVD