CVE Vulnerabilities

CVE-2002-1449

Published: Jul 31, 2002 | Modified: Nov 20, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt.

Affected Software

Name Vendor Start Version End Version
Eupload Frederic_tyndiuk 1.0 (including) 1.0 (including)

References