PT-2007-1634 · Ememberspro · Ememberspro
Published
2007-01-09
·
Updated
2018-10-16
·
CVE-2007-0149
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
EMembersPro version 1.0
Description
The issue allows remote attackers to download a database containing passwords due to insufficient access control. This is possible because sensitive information is stored under the web root, enabling attackers to access it via a direct request.
Recommendations
For EMembersPro version 1.0, consider restricting access to sensitive files, such as the users.mdb database, to prevent unauthorized downloads until a proper fix is available. As a temporary workaround, moving sensitive information outside of the web root can help minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ememberspro