Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g325-25jq-xp25

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/.

Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/.

EPSS

Процентиль: 79%
0.01288
Низкий

Связанные уязвимости

nvd
около 19 лет назад

Sven Moderow GuestBook 0.3a stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for (1) gbook97.mdb or (2) gbook.mdb in ~db/.

EPSS

Процентиль: 79%
0.01288
Низкий