PoC Index

CVE-2013-1814

MEDIUM 4.0EPSS 73.8%

The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.

CVSS v2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
EPSS
73.82% chance of exploitation in the next 30 days, 99th percentile
Published
2013-03-14
Updated
2024-09-17

Proof-of-concept exploits (1)

Metasploit modules (1)

ExploitDB entries (1)

References

Related