CVE-2009-1052
24.03.2009, 14:30
FireAnt 1.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv.Enginsight
Vendor | Product | Version |
---|---|---|
chaozz | fireant | 𝑥 ≤ 1.3 |
chaozz | fireant | 1.0 |
chaozz | fireant | 1.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration