PT-2004-2956 · Xlinesoft · Asprunner

Ferruh Mavituna

·

Publicado

2004-12-31

·

Atualizado

2017-07-11

·

CVE-2004-2060

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ASPRunner version 2.4
Description The issue allows remote attackers to obtain the database by making a direct request to the database filename. The database filename is predictable based on table and field names, such as tablename and fieldname. This predictability may enable attackers to access the database via a direct request to the database filename.
Recommendations For ASPRunner version 2.4, consider moving the database outside of the web root directory to prevent direct access. As a temporary workaround, restrict access to the db directory to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-2060

Produtos afetados

Asprunner