The (1) dlback.php and (2) dlback.cgi scripts in Hot Links allow remote attackers to obtain sensitive information and download the database via a direct request with a modified dl parameter.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/30340 | third party advisory vdb entry |
http://secunia.com/advisories/22970 | third party advisory permissions required |
http://marc.info/?l=bugtraq&m=116373064308228&w=2 | third party advisory mailing list |
http://www.securityfocus.com/bid/21112 | third party advisory vdb entry exploit |
http://www.vupen.com/english/advisories/2006/4585 | vdb entry not applicable |
http://marc.info/?l=bugtraq&m=116370290529916&w=2 | third party advisory mailing list |