PT-2005-4937 · Adp · Adp Forum

Liz0

·

Publicado

2005-12-15

·

Atualizado

2024-02-14

·

CVE-2005-4249

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ADP Forum versions 2.0 through 2.0.3
Description The issue allows remote attackers to obtain user credentials due to sensitive information being stored in plaintext files under the web document root with insufficient access control. This can be achieved via requests to the "forum/users" directory.
Recommendations For ADP Forum versions 2.0 through 2.0.3, consider restricting access to the forum/users directory to minimize the risk of exploitation. As a temporary workaround, limit access to sensitive information stored in plaintext files under the web document root until a proper fix is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4249

Produtos afetados

Adp Forum