Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Soltan_Defacer

Pesquisador deazhteam
#49652de 53,632
5CVSS total
Vulnerabilidades · 1
PT-2006-3741
5.0
2006-06-05
Ashopkart · Ashopkart · CVE-2006-2823
**Name of the Vulnerable Software and Affected Versions** ashopKart 2.0 (aka ashopKart20) **Description** The issue allows remote attackers to download a database due to insufficient access control of sensitive information stored under the web root. This can be achieved via a direct request for specific files, such as 'admin/scart.mdb' and possibly 'admin/scart97.mdb'. **Recommendations** For ashopKart 2.0, restrict access to the `admin/scart.mdb` and `admin/scart97.mdb` files to prevent unauthorized downloads. Consider implementing proper access controls for sensitive information stored under the web root. At the moment, there is no information about a newer version that contains a fix for this vulnerability.