Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Liberum_help_desk | Liberum | 0.97.3 (including) | 0.97.3 (including) |