ATutor 1.5.1, and possibly earlier versions, stores temporary chat logs under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain user chat conversations via direct requests to those files.
References
Link | Resource |
---|---|
http://rgod.altervista.org/atutor151.html | Exploit Vendor Advisory |
http://www.securityfocus.com/bid/14832 | Exploit |
http://securityreason.com/securityalert/9 | |
http://marc.info/?l=bugtraq&m=112671176100432&w=2 |
Configurations
Information
Published : 2005-09-16 15:03
Updated : 2016-10-17 20:31
NVD link : CVE-2005-2956
Mitre link : CVE-2005-2956
JSON object : View
CWE
Products Affected
adaptive_technology_resource_centre
- atutor