ASPApp PortalAPP Remote User Database Access Vulnerability
BID:9354
Info
ASPApp PortalAPP Remote User Database Access Vulnerability
| Bugtraq ID: | 9354 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 04 2004 12:00AM |
| Updated: | Jan 04 2004 12:00AM |
| Credit: | Discovery credited to newbie6290. |
| Vulnerable: |
Iatek PortalApp 0 |
| Not Vulnerable: | |
Discussion
ASPApp PortalAPP Remote User Database Access Vulnerability
A problem has been identified in ASPapp PortalApp when user credentials are stored on a system. Because of this, an attacker may be able to gain unauthorized access to sensitive information.
A problem has been identified in ASPapp PortalApp when user credentials are stored on a system. Because of this, an attacker may be able to gain unauthorized access to sensitive information.
Exploit / POC
ASPApp PortalAPP Remote User Database Access Vulnerability
No exploit is required for this vulnerability.
The following proof-of-concept has been submitted:
http://www.example.com/APP Portall/data/8275.mdb
No exploit is required for this vulnerability.
The following proof-of-concept has been submitted:
http://www.example.com/APP Portall/data/8275.mdb
Solution / Fix
ASPApp PortalAPP Remote User Database Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.