Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/11572 | vdb entry |
http://securityreason.com/securityalert/3780 | third party advisory |
http://www.securityfocus.com/archive/1/315504/30/25460/threaded | mailing list |
http://www.securityfocus.com/bid/7134 | vdb entry exploit |