CVE-2009-1053
24.03.2009, 14:30
chaozzDB 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv.Enginsight
Vendor | Product | Version |
---|---|---|
chaozz | chaozzdb | 𝑥 ≤ 1.2 |
chaozz | chaozzdb | 1.0 |
chaozz | chaozzdb | 1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration