PT-2009-4478 · Vlad Titarenko · Asp Vt Auth

Byalbayx

·

Published

2009-06-09

·

Updated

2017-09-29

·

CVE-2009-2024

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Vlad Titarenko ASP VT Auth version 1.0
Description The issue allows remote attackers to download the database file and obtain usernames and passwords via a direct request for a specific file, zHk8dEes3.txt, due to insufficient access control.
Recommendations For version 1.0, restrict access to sensitive files, such as zHk8dEes3.txt, to prevent remote attackers from downloading the database file. Consider implementing proper access controls to protect sensitive information.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2024

Affected Products

Asp Vt Auth