[] NeoSense

ASP-DEV Discussion Forum 2.0 - Admin Directory Weak Default Permissions

Author: G00db0y
type: webapps
platform: asp
port: 
date_added: 2003-07-13 
date_updated: 2012-11-22 
verified: 1 
codes:  
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/8172/info

It has been reported that a vulnerability exists in ASP-DEV Discussion Forum that exposes potentially sensitive information. Because of this, an attacker may be able to gain access to user credentials.

User credentials are stored in the sub-directory as follows:

http://www.example.com/forum/admin/