PT-2005-4937 · Adp · Adp Forum
Liz0
·
Publicado
2005-12-15
·
Atualizado
2024-02-14
·
CVE-2005-4249
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ADP Forum versions 2.0 through 2.0.3
Description
The issue allows remote attackers to obtain user credentials due to sensitive information being stored in plaintext files under the web document root with insufficient access control. This can be achieved via requests to the "forum/users" directory.
Recommendations
For ADP Forum versions 2.0 through 2.0.3, consider restricting access to the forum/users directory to minimize the risk of exploitation. As a temporary workaround, limit access to sensitive information stored in plaintext files under the web document root until a proper fix is applied.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Adp Forum