PT-2007-1634 · Ememberspro · Ememberspro

Published

2007-01-09

·

Updated

2018-10-16

·

CVE-2007-0149

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions EMembersPro version 1.0
Description The issue allows remote attackers to download a database containing passwords due to insufficient access control. This is possible because sensitive information is stored under the web root, enabling attackers to access it via a direct request.
Recommendations For EMembersPro version 1.0, consider restricting access to sensitive files, such as the users.mdb database, to prevent unauthorized downloads until a proper fix is available. As a temporary workaround, moving sensitive information outside of the web root can help minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0149

Affected Products

Ememberspro