PT-2007-1634 · Ememberspro · Ememberspro
Publicado
2007-01-09
·
Atualizado
2018-10-16
·
CVE-2007-0149
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
EMembersPro version 1.0
Description
The issue allows remote attackers to download a database containing passwords due to insufficient access control. This is possible because sensitive information is stored under the web root, enabling attackers to access it via a direct request.
Recommendations
For EMembersPro version 1.0, consider restricting access to sensitive files, such as the users.mdb database, to prevent unauthorized downloads until a proper fix is available. As a temporary workaround, moving sensitive information outside of the web root can help minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ememberspro