Web Wiz Forum Information Disclosure Vulnerability
BID:7380
Info
Web Wiz Forum Information Disclosure Vulnerability
| Bugtraq ID: | 7380 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2003 12:00AM |
| Updated: | Mar 19 2015 09:40AM |
| Credit: | Discovery of this vulnerability has been credited to "Uziel aka nuJIurpuM" <[email protected]>. |
| Vulnerable: |
Web Wiz Forums Web Wiz Forums 7.0 beta1 Web Wiz Forums Web Wiz Forums 7.0 Web Wiz Forums Web Wiz Forums 6.34 Aelita Software ERDisk for Windows 6.34 |
| Not Vulnerable: |
Web Wiz Forums Web Wiz Forums 7.0 beta1 Web Wiz Forums Web Wiz Forums 7.0 |
Discussion
Web Wiz Forum Information Disclosure Vulnerability
Web Wiz Forum has been reported prone to sensitive information disclosure vulnerability.
An attacker may make a request for and download the underlying Access database file that is used by the Forum application. Sensitive information that is contained in the database and stored in plaintext format may be revealed to the attacker.
Information collected in this way may be used to aid in further attacks against the system.
It should be noted that all versions of Web Wiz Forums have been reported prone to this vulnerability.
Web Wiz Forum has been reported prone to sensitive information disclosure vulnerability.
An attacker may make a request for and download the underlying Access database file that is used by the Forum application. Sensitive information that is contained in the database and stored in plaintext format may be revealed to the attacker.
Information collected in this way may be used to aid in further attacks against the system.
It should be noted that all versions of Web Wiz Forums have been reported prone to this vulnerability.
Exploit / POC
Web Wiz Forum Information Disclosure Vulnerability
The following proof of concept was provided:
http://www.example.com/forum/admin/wwforum.mdb
The following proof of concept was provided:
http://www.example.com/forum/admin/wwforum.mdb
Solution / Fix
Web Wiz Forum Information Disclosure Vulnerability
Solution:
This issue has been addressed in Web Wiz 7.0. Users should contact the vendor to obtain upgrades.
Solution:
This issue has been addressed in Web Wiz 7.0. Users should contact the vendor to obtain upgrades.