PT-2009-4478 · Vlad Titarenko · Asp Vt Auth
Byalbayx
·
Publicado
2009-06-09
·
Atualizado
2017-09-29
·
CVE-2009-2024
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Vlad Titarenko ASP VT Auth version 1.0
Description
The issue allows remote attackers to download the database file and obtain usernames and passwords via a direct request for a specific file, zHk8dEes3.txt, due to insufficient access control.
Recommendations
For version 1.0, restrict access to sensitive files, such as zHk8dEes3.txt, to prevent remote attackers from downloading the database file. Consider implementing proper access controls to protect sensitive information.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Asp Vt Auth