PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Guestbook | Planetmoon | tr3.a.1 (including) | tr3.a.1 (including) |