Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hxpp-755m-rwxg

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for db/iyziforum.mdb. NOTE: some of these details are obtained from third party information.

iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for db/iyziforum.mdb. NOTE: some of these details are obtained from third party information.

EPSS

Процентиль: 87%
0.0347
Низкий

Связанные уязвимости

nvd
около 17 лет назад

iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for db/iyziforum.mdb. NOTE: some of these details are obtained from third party information.

EPSS

Процентиль: 87%
0.0347
Низкий