Compulsive Media CNU5 News.mdb Database Disclosure Vulnerability
BID:11004
Info
Compulsive Media CNU5 News.mdb Database Disclosure Vulnerability
| Bugtraq ID: | 11004 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2004 12:00AM |
| Updated: | Aug 23 2004 12:00AM |
| Credit: | Discovery is credited to "Security .Net Information" <[email protected]>. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Compulsive Media CNU5 News.mdb Database Disclosure Vulnerability
CNU5 is reported prone to a database disclosure vulnerability. It is reported that remote users may download the database file 'news.mdb' and gain access to sensitive information including unencrypted authentication credentials.
CNU5 version 1.2 is reported vulnerable to this issue. CNU5 Extra may be affected as well.
This issue is being retired due to the fact that this is not a vulnerability in the application. Configuring the Web server to restrict access to sensitive files can prevent this problem.
CNU5 is reported prone to a database disclosure vulnerability. It is reported that remote users may download the database file 'news.mdb' and gain access to sensitive information including unencrypted authentication credentials.
CNU5 version 1.2 is reported vulnerable to this issue. CNU5 Extra may be affected as well.
This issue is being retired due to the fact that this is not a vulnerability in the application. Configuring the Web server to restrict access to sensitive files can prevent this problem.
Exploit / POC
Compulsive Media CNU5 News.mdb Database Disclosure Vulnerability
No exploit is required.
The following proof of concept is available:
http://www.example.com/news/news.mdb
http://www.example.com/news.mdb
No exploit is required.
The following proof of concept is available:
http://www.example.com/news/news.mdb
http://www.example.com/news.mdb
Solution / Fix
Compulsive Media CNU5 News.mdb Database Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Compulsive Media CNU5 News.mdb Database Disclosure Vulnerability
References:
References: