CVE-2007-0152 Information

Description

OhhASP stores sensitive information under the web root with insufficient access control which allows remote attackers to download a database containing passwords via a direct request for db/OhhASP.mdb.

Reference

http://64.38.62.221/ariasecucom/forum/showthread.php?t=89 http://osvdb.org/33381 http://www.securityfocus.com/archive/1/456117/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/31342

Share on: