PT-2007-2051 · Siteman · Siteman
Published
2007-01-30
·
Updated
2018-10-16
·
CVE-2007-0593
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Siteman version 1.1.11
Description
The issue allows remote attackers to download a database containing password hashes due to insufficient access control of sensitive information stored under the web root. This can be achieved via a direct request for
data/members.txt.Recommendations
For Siteman version 1.1.11, consider restricting access to the
data/members.txt file to prevent unauthorized downloads. Additionally, review and improve access controls for sensitive information stored under the web root.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Siteman