header-logo
Suggest Exploit
vendor:
ATutor
by:
SecurityFocus
3.3
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: ATutor
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005

ATutor Remote Information Disclosure Vulnerability

ATutor is prone to a remote information disclosure vulnerability. This issue is due to a failure in the application to perform proper access validation before granting access to privileged information. A remote attacker can exploit this vulnerability and make repeated GET requests for the chat logs, effectively retrieving all chat archives. Information obtained may aid an attacker in further attacks.

Mitigation:

Ensure that access validation is performed before granting access to privileged information.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/14832/info

ATutor is prone to a remote information disclosure vulnerability. This issue is due to a failure in the application to perform proper access validation before granting access to privileged information.

A remote attacker can exploit this vulnerability and make repeated GET requests for the chat logs, effectively retrieving all chat archives. Information obtained may aid an attacker in further attacks. 

http://www.example.com/atutor/content/chat/2/msgs/1.message
http://www.example.com/atutor/content/chat/2/msgs/2.message
http://www.example.com/atutor/content/chat/2/msgs/3.message 
cqrsecured