ASP-DEV Discussion Forum 2.0 - Admin Directory Weak Default Permissions
Author: G00db0y
type: webapps
platform: asp
port:
date_added: 2003-07-13
date_updated: 2012-11-22
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/8172/info
It has been reported that a vulnerability exists in ASP-DEV Discussion Forum that exposes potentially sensitive information. Because of this, an attacker may be able to gain access to user credentials.
User credentials are stored in the sub-directory as follows:
http://www.example.com/forum/admin/