vendor:
PHP Classifieds
by:
indoushka
7,5
CVSS
HIGH
E-mail Dump
N/A
CWE
Product Name: PHP Classifieds
Affected Version From: V6.09
Affected Version To: V6.09
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2009
PHP Classifieds V6.09 E-mail Dump Vulnerability
An attacker can exploit this vulnerability by accessing the dump.txt file located in the admin folder or the backup folder of the PHP Classifieds V6.09 application. This will allow the attacker to view the emails of all the users registered on the application.
Mitigation:
Ensure that the application is updated to the latest version and that all the security patches are applied.