NewsTraXor Website Management Script 2.9 Beta - Database Disclosure



EKU-ID: 29459 CVE: OSVDB-ID:
Author: CyberTal0n Published: 2004-04-22 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/10194/info

Reportedly NewsTraXor is affected by a remote database disclosure vulnerability. This issue is due to a design error that allows the database file to be globally readable.

This issue may allow a remote attacker to gain unauthorized administrative access to the affected web application.

www.example.com/news/Dbase/nTrax.mdb