export.php in The Address Book 1.04e writes username and password hash information into a publicly accessible file when dumping the MySQL database contents, which allows remote attackers to obtain sensitive information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/31244 | vdb entry |
http://secunia.com/secunia_research/2006-76/advisory/ | vendor advisory |
http://osvdb.org/32563 | vdb entry |
http://www.securityfocus.com/bid/21870 | vdb entry |
http://secunia.com/advisories/21694 | third party advisory vendor advisory |