peter bassill · operator
$ cve CVE-2005-4880 JSON

CVE-2005-4880 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 2.4% (pctl 83)

Patch early

A public exploit exists.

Description

Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS2.39% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2009-03-31
Last modified2026-06-16

Affected (1)

VendorProduct
jax scriptsjax guestbook

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD