CVE Vulnerabilities

CVE-2004-2060

Published: Dec 31, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.

Affected Software

Name Vendor Start Version End Version
Asprunner Xlinesoft 1.0 1.0
Asprunner Xlinesoft 2.0 2.0
Asprunner Xlinesoft 2.1 2.1
Asprunner Xlinesoft 2.2 2.2
Asprunner Xlinesoft 2.3 2.3
Asprunner Xlinesoft 2.4 2.4

References