UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eventpublisher.txt.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/17647 | vdb entry |
http://secunia.com/advisories/19727 | third party advisory |
http://osvdb.org/ref/24/24236-upoint.txt | |
http://www.osvdb.org/24237 | vdb entry |