Security Advisory

CVE-2008-5762

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-12-30 20:00:00
Last updated 2024-08-07 11:04:44
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for slog_users.txt.