Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remote attackers to download passwords via a direct request for data/users.dat.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Voodoo_chat | Voc-project | 1.0_rc1b (including) | 1.0_rc1b (including) |