CVE-2004-1695
high · 10EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administration feature via a URL that contains an extra leading / (slash).
10
CVSS
10.1%
EPSS (exploit prob.)
95th
EPSS percentile
2004-09-20
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| emulive | server4 | commerce_build_7560 |
Check a specific version with /api/v1/cve/match.
References
- http://marc.info/?l=bugtraq&m=109577497718374&w=2
- http://secunia.com/advisories/12616
- http://www.gulftech.org/?node=research&article_id=00051-09202004
- http://www.securityfocus.com/bid/11226
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17450
- http://marc.info/?l=bugtraq&m=109577497718374&w=2
- http://secunia.com/advisories/12616
- http://www.gulftech.org/?node=research&article_id=00051-09202004
- http://www.securityfocus.com/bid/11226
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17450
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2004-1695