CVE-2012-0263

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
31/12/2013
Last modified:
11/04/2025

Description

monitor/index.php in op5 Monitor and op5 Appliance before 5.5.1 allows remote authenticated users to obtain sensitive information such as database and user credentials via error messages that are triggered by (1) a malformed hoststatustypes parameter to status/service/all or (2) a crafted request to config.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:op5:monitor:*:*:*:*:*:*:*:* 5.5.0 (including)
cpe:2.3:a:op5:monitor:5.3.5:*:*:*:*:*:*:*
cpe:2.3:a:op5:monitor:5.4.0:*:*:*:*:*:*:*
cpe:2.3:a:op5:monitor:5.4.2:*:*:*:*:*:*:*