Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wp9v-5956-j972

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for slog_users.txt.

Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for slog_users.txt.

EPSS

Процентиль: 90%
0.05365
Низкий

Связанные уязвимости

nvd
около 17 лет назад

Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for slog_users.txt.

EPSS

Процентиль: 90%
0.05365
Низкий