PT-2007-1253 · Headstart Solutions · Deskpro

Publicado

2007-02-07

·

Atualizado

2008-09-05

·

CVE-2006-6974

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Headstart Solutions DeskPRO (affected versions not specified)
Description The issue allows remote attackers to access sensitive information due to insufficient access control. This enables attackers to list files in the includes/ directory, obtain SQL credentials via direct requests for config.php and config.php.bak in includes/, and read files in various directories such as email/, admin/graphs/, includes/javascript/, and other includes/ directories. Attackers can also download SQL database data by directly requesting files like data.sql, install.sql, settings.sql, and possibly other files in install/v2data/.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6974

Produtos afetados

Deskpro