5
CVSSv2

CVE-2007-1192

Published: 02/03/2007 Updated: 15/11/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Thomas R. Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access control, which allows remote malicious users to download an admin password hash via a direct request for data/gbconfiguration.dat.

Vulnerable Product Search on Vulmon Subscribe to Product

hyperbook guestbook 1.30

Exploits

source: wwwsecurityfocuscom/bid/22754/info HyperBook Guestbook is prone to an information-disclosure vulnerability because the application fails to protect sensitive information An attacker can exploit this issue to access sensitive information that may lead to other attacks This issue affects version 130; other versions may also be ...