PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for dbbackup.txt.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pad_site_scripts | Phpeasycode | 3.6 (including) | 3.6 (including) |