vendor:
Douran Portal
by:
AJAX Security Team
5.5
CVSS
MEDIUM
File Download/Source Code Disclosure
CWE
Product Name: Douran Portal
Affected Version From: 3.9.7.8
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2010
Douran Portal File Download/Source Code Disclosure Vulnerability
It is possible to bypass the security protections of ?/download.aspx? in Douran Portal and download the hosted files.
Mitigation:
Unknown