CVE-2010-1736 Information

Description

KrM Haber 1.0 stores sensitive information under the web root with insufficient access control which allows remote attackers to download a database via a direct request for d_atabase/Krmdb.mdb.

Reference

http://osvdb.org/64217 http://packetstormsecurity.org/1004-exploits/krmhaber-disclose.txt http://secunia.com/advisories/39700 https://exchange.xforce.ibmcloud.com/vulnerabilities/58284

Share on: