CVE-2005-4880: Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allow
infovulnerability
security
Summary
Jax Guestbook versions 3.1 and 3.31 store sensitive user information, like IP addresses, in directories accessible to the web (the folder a website serves files from), with weak access controls that allow anyone on the internet to view it by directly requesting certain files. Remote attackers can obtain user IP addresses by requesting files like guestbook, guestbook_ips2block, ips2block, and formmailer/logfile.csv.
Vulnerability Details
CVSS Score
5
EPSS (30-day exploit probability)
EPSS: 2.0%
Classification
Attack SophisticationTrivial
Taxonomy References
CWE (Weakness Type)
Original source: https://nvd.nist.gov/vuln/detail/CVE-2005-4880
First tracked: February 15, 2026 at 08:43 PM
Classified by LLM (prompt v3) · confidence: 95%