CVE-2008-6374 Information

Description

CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access control which allows remote attackers to obtain sensitive information via a direct request to db/MailingList.mdb.

Reference

http://secunia.com/advisories/33000 https://exchange.xforce.ibmcloud.com/vulnerabilities/47018 https://www.exploit-db.com/exploits/7325

Share on: