ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords via an HTTP request to a .user file.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/10556.php | vdb entry exploit |
http://www.securityfocus.com/bid/6127 | vdb entry exploit |
http://archives.neohapsis.com/archives/bugtraq/2002-11/0058.html | mailing list exploit vendor advisory |