vendor:
ASTPP
by:
Fabien AUNAY
N/A
CVSS
N/A
Unauthenticated Predictable database backup download
CWE
Product Name: ASTPP
Affected Version From: 4.0.1
Affected Version To: 4.0.1
Patch Exists: NO
Related CWE: -
CPE:
Platforms Tested: Debian 9 - CentOS 7
2019
ASTPP 4.0.1 VoIP Billing – Database Backup Download
When administrator performs a ASTPP backup in web interface (Configuration / Database Restore / Create) the file name follows a semi-predictable pattern located in /var/www/html/astpp/database_backup/. The file name can be FUZZED for data exfiltration with the following pattern: astpp_20200110080136.sql.gz