peter bassill · operator
$ cve CVE-2006-1164 JSON

CVE-2006-1164 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.7% (pctl 86)

Patch early

A public exploit exists.

Description

Nodez 4.6.1.1 and earlier stores sensitive data in the list.gtdat file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password hashes by directly accessing list.gtdat.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.72% — more likely to be exploited than 86% of all CVEs
On CISA KEVno
Public exploityes
Published2006-03-12
Last modified2026-06-16

Affected (1)

VendorProduct
nodeznodez

Public exploits

SourceTitleDate
exploit-dbnodez 4.6.1.1 mercury - Multiple Vulnerabilities2006-03-18

References

→ the Explorer  ·  watch your stack  ·  NVD