UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eventpublisher.txt.
References
Configurations
Information
Published : 2006-04-15 16:02
Updated : 2008-09-05 14:01
NVD link : CVE-2006-1437
Mitre link : CVE-2006-1437
JSON object : View
CWE
Products Affected
upoint
- at1_event_publisher