CVE-2009-0767
EUVD-2009-076706.03.2009, 06:50
Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing credentials via a direct request for job/config.data.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| bookelves | kipper | 2.01 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration