vendor:
BaalASP
by:
indoushka
7.5
CVSS
HIGH
Database Download
532
CWE
Product Name: BaalASP
Affected Version From: 2
Affected Version To: 2
Patch Exists: NO
Related CWE: N/A
CPE: a:baalasp:baalasp:2.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows SP2 Français V.(Pnx2 2.0) + Lunix Français v.(9.4 Ubuntu)
2008
BaalASP 2.0 DB Download Vulnerability
The vulnerability allows an attacker to download the database of the application by accessing the URL http://server/BaalASP/database/baalsmartform.mdb
Mitigation:
Ensure that the application is not exposing any sensitive information to the public.