Vulnerability Details CVE-2006-1437
UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eventpublisher.txt.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.4%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2006-1437
-
cpe:2.3:a:upoint:at1_event_publisher:2003-12-18