ADP Forum 2.0 through 2.0.3 stores sensitive information in plaintext files under the web document root with insufficient access control, which allows remote attackers to obtain user credentials via requests to the forum/users directory.
References
Link | Resource |
---|---|
http://secunia.com/advisories/18027 | Vendor Advisory |
http://securityreason.com/securityalert/253 | |
http://www.blogcu.com/Liz0ziM/144336/ | Exploit Vendor Advisory URL Repurposed |
http://www.securityfocus.com/archive/1/419393/100/0/threaded | |
http://secunia.com/advisories/18027 | Vendor Advisory |
http://securityreason.com/securityalert/253 | |
http://www.blogcu.com/Liz0ziM/144336/ | Exploit Vendor Advisory URL Repurposed |
http://www.securityfocus.com/archive/1/419393/100/0/threaded |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:03
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/18027 - Vendor Advisory | |
References | () http://securityreason.com/securityalert/253 - | |
References | () http://www.blogcu.com/Liz0ziM/144336/ - Exploit, Vendor Advisory, URL Repurposed | |
References | () http://www.securityfocus.com/archive/1/419393/100/0/threaded - |
14 Feb 2024, 01:17
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) http://www.blogcu.com/Liz0ziM/144336/ - Exploit, Vendor Advisory, URL Repurposed |
Information
Published : 2005-12-15 11:03
Updated : 2024-11-21 00:03
NVD link : CVE-2005-4249
Mitre link : CVE-2005-4249
CVE.ORG link : CVE-2005-4249
JSON object : View
Products Affected
adp
- adp_forum
CWE