{"api_version":"1","generated_at":"2026-05-30T21:38:07+00:00","cve":"CVE-2004-2671","urls":{"html":"https://cve.report/CVE-2004-2671","api":"https://cve.report/api/cve/CVE-2004-2671.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-2671","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-2671"},"summary":{"title":"CVE-2004-2671","description":"mod.php in eNdonesia 8.3 allows remote attackers to obtain sensitive information via certain direct requests, and certain requests with invalid parameter values, which reveal the path in various error messages, as demonstrated by the (1) mod and (2) cid parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/370855","name":"http://www.securityfocus.com/archive/1/370855","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/13042","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/13042","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1010864","name":"http://securitytracker.com/id?1010864","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"eNdonesia 'mod.php' Input Validation Vulnerability in Search 'query' Parameter Permits Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/8507","name":"http://www.securityfocus.com/bid/8507","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"eNdonesia Mod Parameter Path Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/12231","name":"http://secunia.com/advisories/12231","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - eNdonesia Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://echo.or.id/adv/adv02-y3dips-2004.txt","name":"http://echo.or.id/adv/adv02-y3dips-2004.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"ECHO","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-2671","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-2671","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"2671","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"endonesia","cpe5":"endonesia","cpe6":"8.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:36:25.243Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20040804 Multiple vulnerabilities in eNdonesia CMS","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/370855"},{"name":"12231","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/12231"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://echo.or.id/adv/adv02-y3dips-2004.txt"},{"name":"1010864","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1010864"},{"name":"8507","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/8507"},{"name":"endonesia-mod-path-disclosure(13042)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/13042"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-08-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"mod.php in eNdonesia 8.3 allows remote attackers to obtain sensitive information via certain direct requests, and certain requests with invalid parameter values, which reveal the path in various error messages, as demonstrated by the (1) mod and (2) cid parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20040804 Multiple vulnerabilities in eNdonesia CMS","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/370855"},{"name":"12231","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/12231"},{"tags":["x_refsource_MISC"],"url":"http://echo.or.id/adv/adv02-y3dips-2004.txt"},{"name":"1010864","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1010864"},{"name":"8507","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/8507"},{"name":"endonesia-mod-path-disclosure(13042)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/13042"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-2671","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"mod.php in eNdonesia 8.3 allows remote attackers to obtain sensitive information via certain direct requests, and certain requests with invalid parameter values, which reveal the path in various error messages, as demonstrated by the (1) mod and (2) cid parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20040804 Multiple vulnerabilities in eNdonesia CMS","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/370855"},{"name":"12231","refsource":"SECUNIA","url":"http://secunia.com/advisories/12231"},{"name":"http://echo.or.id/adv/adv02-y3dips-2004.txt","refsource":"MISC","url":"http://echo.or.id/adv/adv02-y3dips-2004.txt"},{"name":"1010864","refsource":"SECTRACK","url":"http://securitytracker.com/id?1010864"},{"name":"8507","refsource":"BID","url":"http://www.securityfocus.com/bid/8507"},{"name":"endonesia-mod-path-disclosure(13042)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/13042"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-2671","datePublished":"2007-01-05T02:00:00.000Z","dateReserved":"2007-01-04T00:00:00.000Z","dateUpdated":"2024-08-08T01:36:25.243Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:endonesia:endonesia:8.3:*:*:*:*:*:*:*","matchCriteriaId":"67EC4834-E498-4B44-90FD-3A747C509FB8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"2671","Ordinal":"1","Title":"CVE-2004-2671","CVE":"CVE-2004-2671","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"2671","Ordinal":"1","NoteData":"mod.php in eNdonesia 8.3 allows remote attackers to obtain sensitive information via certain direct requests, and certain requests with invalid parameter values, which reveal the path in various error messages, as demonstrated by the (1) mod and (2) cid parameters.","Type":"Description","Title":"CVE-2004-2671"},{"CveYear":"2004","CveId":"2671","Ordinal":"2","NoteData":"2007-01-04","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"2671","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}