Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7f3x-h25w-q7w7

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a direct request to admin/passwd.

TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a direct request to admin/passwd.

EPSS

Процентиль: 94%
0.12875
Средний

Связанные уязвимости

nvd
почти 20 лет назад

TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a direct request to admin/passwd.

EPSS

Процентиль: 94%
0.12875
Средний