PT-2009-3351 · Downloadcenter · Downloadcenter
Published
2009-02-24
·
Updated
2017-08-17
·
CVE-2009-0732
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Downloadcenter version 2.1
Description
The issue allows remote attackers to obtain user credentials and other sensitive information via a direct request to a file stored under the web root with insufficient access control. The file
common.h is accessible, which contains sensitive information.Recommendations
For Downloadcenter version 2.1, restrict access to the
common.h file to prevent remote attackers from obtaining sensitive information. Consider moving the file outside of the web root or implementing proper access controls to mitigate the risk.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Downloadcenter