vendor:
ASPPortal
by:
CWH Underground
7.5
CVSS
HIGH
Remote Database Disclosure
CWE
Product Name: ASPPortal
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2008
ASPPortal Free Version Remote Database Disclosure Vulnerability
The ASPPortal Free Version is vulnerable to remote database disclosure. An attacker can access the database by accessing the URL http://[Target]/[aspportal_path]/Data/ASPPortal.mdb.
Mitigation:
The vendor should release a patch to fix this vulnerability. Users are advised to apply the patch as soon as it is available. In the meantime, it is recommended to restrict access to the affected URL or remove the vulnerable component.