PT-2005-2233 · Unknown · Shoutbox Script
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Shoutbox SCRIPT versions 3.0.2 and earlier
Description
The issue allows remote attackers to obtain sensitive information by making a direct request to "db/settings.dat", which displays usernames and password hashes.
Recommendations
For Shoutbox SCRIPT versions 3.0.2 and earlier, restrict access to the db/settings.dat file to prevent unauthorized disclosure of sensitive information. Consider implementing proper access controls and security measures to protect sensitive data.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Shoutbox Script