Back

CVE-2004-2506

Unparsed web content delivery vulnerability in WIKINDX before 0.9.9g allows remote attackers to obtain sensitive information via a direct HTTP request to the config.inc file.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (14)

Vendor Product Version
wikindx wikindx 0.9.1
wikindx wikindx 0.9.2
wikindx wikindx 0.9.3
wikindx wikindx 0.9.4
wikindx wikindx 0.9.5
wikindx wikindx 0.9.6
wikindx wikindx 0.9.7
wikindx wikindx 0.9.8
wikindx wikindx 0.9.9
wikindx wikindx 0.9.9b
wikindx wikindx 0.9.9c
wikindx wikindx 0.9.9d
wikindx wikindx 0.9.9e
wikindx wikindx 0.9.9f

GitHub Security Advisory GHSA-5872-q7c3-cvqr

Unparsed web content delivery vulnerability in WIKINDX before 0.9.9g allows remote attackers to...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 1.39%

Top 30% most likely to be exploited

Threat Score 20.4 / 100

Data Sources

NVD EPSS GitHub