NEXTWEB (i)Site stores databases under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to databases/Users.mdb.
Threat-Mapped Scoring
Score: 3.0
Priority: P2 - Serious (High)
S1 – Steal Customer Account Information
EPSS
Score: 0.00676 Percentile:
0.70558
CVSS Scoring
CVSS v2 Score: 5.0
Severity:
Mapped CWE(s)
CWE-552
: Files or Directories Accessible to External Parties
All CAPEC(s)
CAPEC-150: Collect Data from Common Resource Locations
CAPEC-639: Probe System Files
CAPEC(s) with Mapped TTPs
CAPEC-150: Collect Data from Common Resource Locations
Mapped TTPs: