vendor:
iDevAffiliate
by:
indoushka
7.5
CVSS
HIGH
Backup
22
CWE
Product Name: iDevAffiliate
Affected Version From: 4
Affected Version To: 4
Patch Exists: NO
Related CWE: N/A
CPE: idevaffiliate
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows SP2 Français V.(Pnx2 2.0) + Lunix Français v.(9.4 Ubuntu)
2009
iDevAffiliate v4.0 Backup Vulnerability
The vulnerability exists in iDevAffiliate v4.0, which allows an attacker to access the backup directory of the application. By accessing the backup directory, the attacker can download the backup files and gain access to the application's data.
Mitigation:
Ensure that the backup directory is not accessible from the web server.