5
CVSSv2

CVE-2003-1541

Published: 31/12/2003 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote malicious users to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt.

Vulnerable Product Search on Vulmon Subscribe to Product

planetmoon guestbook tr3.a.1

Exploits

source: wwwsecurityfocuscom/bid/7167/info A vulnerability has been reported in Planetmoon Guestbook It has been reported that remote users may be able to retrieve clear text password lists Access to this data may allow an attacker to carry out further attacks against a target user [somehost]/[gb_dir]/files/passwdtxt ...