PT-2009-4478 · Vlad Titarenko · Asp Vt Auth
Byalbayx
·
Published
2009-06-09
·
Updated
2017-09-29
·
CVE-2009-2024
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Vlad Titarenko ASP VT Auth version 1.0
Description
The issue allows remote attackers to download the database file and obtain usernames and passwords via a direct request for a specific file, zHk8dEes3.txt, due to insufficient access control.
Recommendations
For version 1.0, restrict access to sensitive files, such as zHk8dEes3.txt, to prevent remote attackers from downloading the database file. Consider implementing proper access controls to protect sensitive information.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asp Vt Auth