CVE-2009-1322
17.04.2009, 14:08
ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for database/aspProductCatalog.mdb.Enginsight
Vendor | Product | Version |
---|---|---|
humayun_shabbir_bhutta | asp_product_catalog | 1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration