PT-2009-3351 · Downloadcenter · Downloadcenter
Publicado
2009-02-24
·
Atualizado
2017-08-17
·
CVE-2009-0732
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Downloadcenter version 2.1
Description
The issue allows remote attackers to obtain user credentials and other sensitive information via a direct request to a file stored under the web root with insufficient access control. The file
common.h is accessible, which contains sensitive information.Recommendations
For Downloadcenter version 2.1, restrict access to the
common.h file to prevent remote attackers from obtaining sensitive information. Consider moving the file outside of the web root or implementing proper access controls to mitigate the risk.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Downloadcenter