CVE Vulnerabilities

CVE-2002-1449

Published: Jul 31, 2002 | Modified: Sep 10, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt.

Affected Software

Name Vendor Start Version End Version
Eupload Frederic_tyndiuk 1.0 (including) 1.0 (including)

References