4.3
CVSSv2

CVE-2006-7086

Published: 02/03/2007 Updated: 10/06/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The (1) dlback.php and (2) dlback.cgi scripts in Hot Links allow remote malicious users to obtain sensitive information and download the database via a direct request with a modified dl parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

mrcgiguy hot links -

Exploits

source: wwwsecurityfocuscom/bid/21112/info Hot Links is prone to an information-disclosure vulnerability because it fails to authenticate the user during specific download requests An attacker can exploit this issue to retrieve administrative backup files Information obtained may aid in further attacks All versions of Hot Links SQL-P ...