Ocean12 Calendar Manager Gold 2.04 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12cal.mdb.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/32409 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46133 | vdb entry |
http://packetstorm.linuxsecurity.com/0810-exploits/ocean12-database.txt | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/46694 | vdb entry |