Guestbook Sensitive Information Disclosure Weakness
BID:7320
Info
Guestbook Sensitive Information Disclosure Weakness
| Bugtraq ID: | 7320 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2003 12:00AM |
| Updated: | Apr 10 2003 12:00AM |
| Credit: | Discovery of this weakness has been credited to Over_G <[email protected]>. |
| Vulnerable: |
Guestbook Guestbook 4.0 |
| Not Vulnerable: | |
Discussion
Guestbook Sensitive Information Disclosure Weakness
Guestbook has been reported prone to a sensitive information disclosure weakness.
An attacker may disclose sensitive information regarding the Super Guestbook install by sending a HTTP request for the Guest Book passwd file. Administration credentials are displayed in the attacker's browser.
Guestbook has been reported prone to a sensitive information disclosure weakness.
An attacker may disclose sensitive information regarding the Super Guestbook install by sending a HTTP request for the Guest Book passwd file. Administration credentials are displayed in the attacker's browser.