Ocean12 Contact Manager Pro 1.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12con.mdb.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/32409 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46133 | vdb entry |
https://www.exploit-db.com/exploits/7244 | exploit |
http://packetstorm.linuxsecurity.com/0810-exploits/ocean12-database.txt |