PT-2010-1629 · Unknown · Angelo-Emlak

Lionturk

·

Published

2010-04-27

·

Updated

2017-08-17

·

CVE-2009-4820

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Angelo-Emlak version 1.0
Description The issue allows remote attackers to download a database due to insufficient access control. Sensitive information is stored under the web root, enabling attackers to access the database via a direct request for veribaze/angelo.mdb.
Recommendations For Angelo-Emlak version 1.0, consider restricting access to the veribaze/angelo.mdb file to prevent unauthorized downloads until a proper fix is applied. Additionally, review and improve access controls for sensitive information stored under the web root.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4820

Affected Products

Angelo-Emlak