PT-2007-2006 · Toxiclab · Toxiclab Shoutbox

Published

2007-01-29

·

Updated

2018-10-16

·

CVE-2007-0546

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Toxiclab Shoutbox version 1
Description The issue allows remote attackers to download a database containing passwords via a direct request for db.mdb due to insufficient access control. This is because sensitive information is stored under the web root.
Recommendations For Toxiclab Shoutbox version 1, consider restricting access to the db.mdb file until a proper fix is available. As a temporary workaround, moving sensitive information outside of the web root can help minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0546

Affected Products

Toxiclab Shoutbox