CVE-2014-10079

In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of the HTML source code, which is disclosed because of incorrect processing of an index.php/ trailing slash.
References
Link Resource
https://cxsecurity.com/issue/WLB-2018120091 Exploit Third Party Advisory
https://packetstormsecurity.com/files/127786/Vembu-Backup-Disaster-Recovery-6.1-Follow-Up.html Third Party Advisory VDB Entry
https://seclists.org/fulldisclosure/2014/Aug/8 Mailing List Third Party Advisory
https://www.exploit-db.com/exploits/46549/ Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:vembu:storegrid:4.4:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-02-23 14:29

Updated : 2024-02-04 20:03


NVD link : CVE-2014-10079

Mitre link : CVE-2014-10079

CVE.ORG link : CVE-2014-10079


JSON object : View

Products Affected

vembu

  • storegrid
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor