CVE-2003-1553

Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sips:sips:0.2.2:*:*:*:*:*:*:*

History

20 Nov 2024, 23:47

Type Values Removed Values Added
References () http://securityreason.com/securityalert/3780 - () http://securityreason.com/securityalert/3780 -
References () http://www.securityfocus.com/archive/1/315504/30/25460/threaded - () http://www.securityfocus.com/archive/1/315504/30/25460/threaded -
References () http://www.securityfocus.com/bid/7134 - Exploit () http://www.securityfocus.com/bid/7134 - Exploit
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/11572 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/11572 -

Information

Published : 2003-12-31 05:00

Updated : 2025-04-03 01:03


NVD link : CVE-2003-1553

Mitre link : CVE-2003-1553

CVE.ORG link : CVE-2003-1553


JSON object : View

Products Affected

sips

  • sips
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor