PT-2006-6988 · Unknown · Uploadscript

Hack2Prison

·

Publicado

2006-12-07

·

Atualizado

2018-10-17

·

CVE-2006-6377

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Uploadscript versions 1.2 and earlier
Description The issue allows remote attackers to obtain the admin password hash due to insufficient access control of sensitive data stored under the web root. This can be achieved via a direct request for "/password.txt" API endpoint.
Recommendations For Uploadscript versions 1.2 and earlier, consider restricting access to the "/password.txt" file to prevent unauthorized access until a fix is available. Additionally, review and strengthen access controls for sensitive data stored under the web root.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6377

Produtos afetados

Uploadscript