CVE-2003-1541 describes a critical vulnerability in PlanetMoon Guestbook tr3.a, where sensitive information, including admin and other passwords, is stored in plaintext under the web root in files/passwd.txt with insufficient access control. This allows unauthenticated remote attackers to directly access and retrieve these credentials. The vulnerability has a CVSS score of 5.0 (medium severity) due to its low attack complexity and the potential for complete confidentiality compromise, as indicated by its high FAUCET Risk Score of 93/100. While not listed in CISA's KEV catalog, exploit code is publicly available on ExploitDB (EDB-22408), and the vulnerability has garnered significant community discussion with 10 mentions, suggesting awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
tr3.a.1CPE matchmatch criteria | cpe:2.3:a:planetmoon:guestbook:tr3.a.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.