Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wpr7-r9cj-c64p

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup via a direct request to a backup/backup-yyyy-dd-mm.sql filename.

IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup via a direct request to a backup/backup-yyyy-dd-mm.sql filename.

EPSS

Процентиль: 93%
0.10277
Средний

Дефекты

CWE-200

Связанные уязвимости

nvd
больше 17 лет назад

IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup via a direct request to a backup/backup-yyyy-dd-mm.sql filename.

EPSS

Процентиль: 93%
0.10277
Средний

Дефекты

CWE-200