|
|||||||||||
|
ASP-CMS version 1 default password location.
From: <joseph.giron13(at)gmail.com>
Date: Sat Sep 29 2007 - 22:29:21 EDT
http://asp-cms.sourceforge.net/ A vulnerability exists within the content management system ASP-CMS that allows a remote user to see the username and password of the content management system itsself. the user/pass combo along with all the other settings of the application are stored in an MDB file in the folder mdb-database. Attackers can input the following into an affected site: http://www.example.com/asp-cms/mdb-database/ASP-CMS_v100.mdb The fix would be to add place the file somewhere else on the filesystem out of reach of the http area. Received on Mon Oct 1 15:35:16 2007 This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:18:43 EDT |
||||||||||
|
|||||||||||