CVE-2008-6771 describes a sensitive information disclosure vulnerability in YourPlace 1.0.2 and earlier, where remote attackers can access system details by directly requesting the phpinfo.php file. This vulnerability carries a CVSS score of 5.0, indicating a medium severity due to its low attack complexity and potential for partial confidentiality impact. While not listed on the KEV catalog or Hot List, an ExploitDB entry (EDB-7545) suggests the existence of exploit code, including for remote code execution, despite a lack of broader community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.2CPE matchmatch criteria | cpe:2.3:a:peterselie:yourplace:*:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:peterselie:yourplace:1.0:*:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:peterselie:yourplace:1.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.