LOW · 2.1

CVE-2004-2398

Netenberg Fantastico De Luxe 2.8 uses database file names that contain the associated usernames, which allows local users to determine valid usernames and conduct brute force attacks by reading the fi...

Vulnerability Description

Netenberg Fantastico De Luxe 2.8 uses database file names that contain the associated usernames, which allows local users to determine valid usernames and conduct brute force attacks by reading the file names from /var/lib/mysql, which is assigned world-readable permissions by cPanel 9.3.0 R5.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
NetenbergFantastico De Luxe2.8

References

FAQ

What is CVE-2004-2398?

CVE-2004-2398 is a vulnerability with a CVSS score of 2.1 (LOW). Netenberg Fantastico De Luxe 2.8 uses database file names that contain the associated usernames, which allows local users to determine valid usernames and conduct brute force attacks by reading the fi...

How severe is CVE-2004-2398?

CVE-2004-2398 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-2398?

Check the references section above for vendor advisories and patch information. Affected products include: Netenberg Fantastico De Luxe.