CVE-2009-1051
24.03.2009, 14:30
FubarForum 1.6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv.Enginsight
Vendor | Product | Version |
---|---|---|
chaozz | fubarforum | 𝑥 ≤ 1.6 |
chaozz | fubarforum | 1.0 |
chaozz | fubarforum | 1.1 |
chaozz | fubarforum | 1.2 |
chaozz | fubarforum | 1.3 |
chaozz | fubarforum | 1.4 |
chaozz | fubarforum | 1.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration