PT-2007-4276 · Techno Dreams · Techno Dreams Web Directory / Search Engine

Published

2007-06-01

·

Updated

2017-07-29

·

CVE-2007-2979

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Techno Dreams Web Directory / Search Engine version 2.0
Description: The issue allows remote attackers to download the database via a direct request for Database.mdb due to insufficient access control of sensitive information stored under the web root.
Recommendations: For version 2.0, restrict access to the Database.mdb file to prevent unauthorized downloads, and consider implementing proper access controls for sensitive information stored under the web root.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2979

Affected Products

Techno Dreams Web Directory / Search Engine