CVE-2009-2602
27.07.2009, 14:30
R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for admin.mdb.Enginsight
Vendor | Product | Version |
---|---|---|
r2newsletter | r2_newsletter_lite | * |
r2newsletter | r2_newsletter_pro | * |
r2newsletter | r2_newsletter_stats | * |
𝑥
= Vulnerable software versions
Common Weakness Enumeration