CVE-2005-4880 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 2.4% (pctl 83)
Patch early
A public exploit exists.
Description
Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 2.39% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-03-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| jax scripts | jax guestbook |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Jax PHP Scripts 1.0/1.34/2.14/3.31 - Guestbook File Client IP Disclosure | 2005-08-05 |
| exploit-db | Jax PHP Scripts 1.0/1.34/2.14/3.31 - guestbook_ips2block Banned IP List Disclosure | 2005-08-05 |
| exploit-db | Jax PHP Scripts 1.0/1.34/2.14/3.31 - ips2block Banned IP List Disclosure | 2005-08-05 |
| exploit-db | Jax PHP Scripts 1.0/1.34/2.14/3.31 - logfile.csv User IP Disclosure | 2005-08-05 |
References
→ the Explorer · watch your stack · NVD