Ocean12 Membership Manager Pro stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12member.mdb.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/32409 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46133 | vdb entry |
http://packetstorm.linuxsecurity.com/0810-exploits/ocean12-database.txt | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46693 | vdb entry |