Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=93582550911564&w=2 | mailing list |