Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.17323
Category:Web application abuses
Title:aeNovo Database Content Disclosure Vulnerability
Summary:Due to improper file permission settings on the database directory of; aeNovo it is possible for a remote attacker to download the product's database file and grab from it; sensitive information.
Description:Summary:
Due to improper file permission settings on the database directory of
aeNovo it is possible for a remote attacker to download the product's database file and grab from it
sensitive information.

Solution:
Restrict access the aeNovo's database file or directory by setting
file/directory restrictions.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

CopyrightCopyright (C) 2005 Noam Rathaus

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.