PT-2006-6988 · Unknown · Uploadscript
Hack2Prison
·
Publicado
2006-12-07
·
Atualizado
2018-10-17
·
CVE-2006-6377
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Uploadscript versions 1.2 and earlier
Description
The issue allows remote attackers to obtain the admin password hash due to insufficient access control of sensitive data stored under the web root. This can be achieved via a direct request for "/password.txt" API endpoint.
Recommendations
For Uploadscript versions 1.2 and earlier, consider restricting access to the "/password.txt" file to prevent unauthorized access until a fix is available. Additionally, review and strengthen access controls for sensitive data stored under the web root.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Uploadscript