eyeOS 0.8.4 stores usrinfo.xml under the web document root with insufficient access control, which allows remote attackers to obtain user credentials.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Eyeos |
Eyeos_project |
0.8.4 (including) |
0.8.4 (including) |
References