CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/6995 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/11447 | vdb entry |
http://www.securityfocus.com/archive/1/313580 | exploit mailing list |
http://securityreason.com/securityalert/3259 | third party advisory |