PT-2006-6988 · Unknown · Uploadscript
Hack2Prison
·
Published
2006-12-07
·
Updated
2018-10-17
·
CVE-2006-6377
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Uploadscript versions 1.2 and earlier
Description
The issue allows remote attackers to obtain the admin password hash due to insufficient access control of sensitive data stored under the web root. This can be achieved via a direct request for "/password.txt" API endpoint.
Recommendations
For Uploadscript versions 1.2 and earlier, consider restricting access to the "/password.txt" file to prevent unauthorized access until a fix is available. Additionally, review and strengthen access controls for sensitive data stored under the web root.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Uploadscript