CVE-2014-10079 EXPLOIT
5.3
MEDIUM · CVSS 3.0 · EPSS 8.7% (pctl 95)
Patch early
A public exploit exists.
Description
In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed because of incorrect processing of an index.php/ trailing slash.
Scoring
| CVSS | 5.3 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 8.75% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-02-23 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| vembu | storegrid |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Vembu Storegrid Web Interface 4.4.0 - Multiple Vulnerabilities | 2019-03-15 |
References
- https://cxsecurity.com/issue/WLB-2018120091
- https://packetstormsecurity.com/files/127786/Vembu-Backup-Disaster-Recovery-6.1-Follow-Up.html
- https://seclists.org/fulldisclosure/2014/Aug/8
- https://www.exploit-db.com/exploits/46549/
- https://cxsecurity.com/issue/WLB-2018120091
- https://packetstormsecurity.com/files/127786/Vembu-Backup-Disaster-Recovery-6.1-Follow-Up.html
- https://seclists.org/fulldisclosure/2014/Aug/8
- https://www.exploit-db.com/exploits/46549/
→ the Explorer · watch your stack · NVD