PT-2006-6988 · Unknown · Uploadscript

Hack2Prison

·

Published

2006-12-07

·

Updated

2018-10-17

·

CVE-2006-6377

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Uploadscript versions 1.2 and earlier
Description The issue allows remote attackers to obtain the admin password hash due to insufficient access control of sensitive data stored under the web root. This can be achieved via a direct request for "/password.txt" API endpoint.
Recommendations For Uploadscript versions 1.2 and earlier, consider restricting access to the "/password.txt" file to prevent unauthorized access until a fix is available. Additionally, review and strengthen access controls for sensitive data stored under the web root.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6377

Affected Products

Uploadscript