vendor:
FlatFile
by:
ViRuSMaN
8,8
CVSS
HIGH
FlatFile system Remote Password Disclouse
N/A
CWE
Product Name: FlatFile
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
FlatFile system Remote Password Disclouse Vulnerability
A vulnerability in the FlatFile system allows an attacker to remotely disclose the password of the admin user. This is due to the fact that the userlist.txt file is publicly accessible and contains the password of the admin user before the admin name.
Mitigation:
The userlist.txt file should be removed or restricted from public access.