eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt.
References
Configurations
Information
Published : 2002-07-30 21:00
Updated : 2008-09-10 12:14
NVD link : CVE-2002-1449
Mitre link : CVE-2002-1449
JSON object : View
CWE
Products Affected
frederic_tyndiuk
- eupload