eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Eupload |
Frederic_tyndiuk |
1.0 (including) |
1.0 (including) |
References