ADP Forum 2.0 through 2.0.3 stores sensitive information in plaintext files under the web document root with insufficient access control, which allows remote attackers to obtain user credentials via requests to the forum/users directory.
References
Link | Resource |
---|---|
http://www.blogcu.com/Liz0ziM/144336/ | Exploit Vendor Advisory |
http://secunia.com/advisories/18027 | Vendor Advisory |
http://securityreason.com/securityalert/253 | |
http://www.securityfocus.com/archive/1/419393/100/0/threaded |
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-12-15 03:03
Updated : 2018-10-19 08:40
NVD link : CVE-2005-4249
Mitre link : CVE-2005-4249
JSON object : View
CWE
Products Affected
adp
- adp_forum