PT-2007-4276 · Techno Dreams · Techno Dreams Web Directory / Search Engine

Publicado

2007-06-01

·

Atualizado

2017-07-29

·

CVE-2007-2979

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Techno Dreams Web Directory / Search Engine version 2.0
Description: The issue allows remote attackers to download the database via a direct request for Database.mdb due to insufficient access control of sensitive information stored under the web root.
Recommendations: For version 2.0, restrict access to the Database.mdb file to prevent unauthorized downloads, and consider implementing proper access controls for sensitive information stored under the web root.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2979

Produtos afetados

Techno Dreams Web Directory / Search Engine