{"api_version":"1","generated_at":"2026-07-23T06:38:59+00:00","cve":"CVE-2004-2588","urls":{"html":"https://cve.report/CVE-2004-2588","api":"https://cve.report/api/cve/CVE-2004-2588.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-2588","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-2588"},"summary":{"title":"CVE-2004-2588","description":"Intentional information leak in phpinfo.php in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allows remote attackers to obtain sensitive information such as the configuration of the web server and the PHP application.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/9983","name":"http://www.securityfocus.com/bid/9983","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"XMB Forum Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1009561","name":"http://securitytracker.com/id?1009561","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"XMB Forum 'forumdisplay.php' and Other Scripts Permit SQL Injection and Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.xmbforum2.com/index.php?title=Security_Issue_History","name":"https://docs.xmbforum2.com/index.php?title=Security_Issue_History","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Issue History - XMBdocs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/4643","name":"http://www.osvdb.org/4643","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=108032355905265&w=2","name":"http://marc.info/?l=bugtraq&m=108032355905265&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15656","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15656","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2004-03/0265.html","name":"http://archives.neohapsis.com/archives/bugtraq/2004-03/0265.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Neohapsis Archives - Bugtraq - #0265 - [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 SP3 and 1.9 beta]","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-2588","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-2588","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"2588","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xmb_software","cpe5":"xmb_forum","cpe6":"1.9_nexus_beta","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2004-2588","organization":"XMB","lastmodified":"2021-04-23","contributor":"Robert Chapin","statementText":"XMB versions 1.9.8 and later were checked and are not vulnerable. Upgrades are available at https://www.xmbforum2.com/","cve_year":"2004","cve_id":"2588","crc32":"08dfc33e"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:29:14.123Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 Partagium SP3 and 1.9 Nexus Beta]","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=108032355905265&w=2"},{"name":"4643","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/4643"},{"name":"1009561","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1009561"},{"name":"xmb-phpinfo-obtain-information(15656)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15656"},{"name":"9983","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/9983"},{"name":"20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 SP3 and 1.9 beta]","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2004-03/0265.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://docs.xmbforum2.com/index.php?title=Security_Issue_History"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-03-26T00:00:00.000Z","descriptions":[{"lang":"en","value":"Intentional information leak in phpinfo.php in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allows remote attackers to obtain sensitive information such as the configuration of the web server and the PHP application."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2021-04-29T14:37:03.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 Partagium SP3 and 1.9 Nexus Beta]","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=108032355905265&w=2"},{"name":"4643","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/4643"},{"name":"1009561","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1009561"},{"name":"xmb-phpinfo-obtain-information(15656)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15656"},{"name":"9983","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/9983"},{"name":"20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 SP3 and 1.9 beta]","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2004-03/0265.html"},{"tags":["x_refsource_MISC"],"url":"https://docs.xmbforum2.com/index.php?title=Security_Issue_History"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-2588","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Intentional information leak in phpinfo.php in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allows remote attackers to obtain sensitive information such as the configuration of the web server and the PHP application."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 Partagium SP3 and 1.9 Nexus Beta]","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=108032355905265&w=2"},{"name":"4643","refsource":"OSVDB","url":"http://www.osvdb.org/4643"},{"name":"1009561","refsource":"SECTRACK","url":"http://securitytracker.com/id?1009561"},{"name":"xmb-phpinfo-obtain-information(15656)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15656"},{"name":"9983","refsource":"BID","url":"http://www.securityfocus.com/bid/9983"},{"name":"20040326 [waraxe-2004-SA#012 - Multiple vulnerabilities in XMB Forum 1.8 SP3 and 1.9 beta]","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2004-03/0265.html"},{"name":"https://docs.xmbforum2.com/index.php?title=Security_Issue_History","refsource":"MISC","url":"https://docs.xmbforum2.com/index.php?title=Security_Issue_History"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-2588","datePublished":"2005-11-28T23:00:00.000Z","dateReserved":"2005-11-28T00:00:00.000Z","dateUpdated":"2024-08-08T01:29:14.123Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:xmb_software:xmb_forum:1.9_nexus_beta:*:*:*:*:*:*:*","matchCriteriaId":"5DE120E2-BC89-47DF-8C7D-F49F7F86FF1A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"2588","Ordinal":"1","Title":"CVE-2004-2588","CVE":"CVE-2004-2588","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"2588","Ordinal":"1","NoteData":"Intentional information leak in phpinfo.php in XMB (aka extreme message board) 1.9 beta (aka Nexus beta) allows remote attackers to obtain sensitive information such as the configuration of the web server and the PHP application.","Type":"Description","Title":"CVE-2004-2588"},{"CveYear":"2004","CveId":"2588","Ordinal":"2","NoteData":"2005-11-28","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"2588","Ordinal":"3","NoteData":"2021-04-29","Type":"Other","Title":"Modified"}]}}}