ASP-DEV Discussion Forum 2.0 - Admin Directory Weak Default Permissions

Author: G00db0y
type: webapps
platform: asp
port: 0
date_added: 2003-07-13
date_updated: 2012-11-22
verified: 1
codes: 
tags: 
aliases: 
screenshot_url: 
application_url: 

source: https://www.securityfocus.com/bid/8172/info

It has been reported that a vulnerability exists in ASP-DEV Discussion Forum that exposes potentially sensitive information. Because of this, an attacker may be able to gain access to user credentials.

User credentials are stored in the sub-directory as follows:

http://www.example.com/forum/admin/
↑