PT-2005-2233 · Unknown · Shoutbox Script
Corryl
·
Publicado
2005-04-22
·
Atualizado
2017-07-11
·
CVE-2005-1220
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Shoutbox SCRIPT versions 3.0.2 and earlier
Description
The issue allows remote attackers to obtain sensitive information by making a direct request to "db/settings.dat", which displays usernames and password hashes.
Recommendations
For Shoutbox SCRIPT versions 3.0.2 and earlier, restrict access to the db/settings.dat file to prevent unauthorized disclosure of sensitive information. Consider implementing proper access controls and security measures to protect sensitive data.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Shoutbox Script