Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remote attackers to download passwords via a direct request for data/users.dat.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/31221 | vdb entry |
https://www.exploit-db.com/exploits/3044 | exploit |