Beveiligingsadvies

CVE-2006-1412

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2006-03-28 11:00:00
Laatst bijgewerkt 2024-08-07 17:12:21
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a direct request to admin/passwd.