vendor:
ADP Forum
by:
Dr Max Virus
9
CVSS
CRITICAL
Remote Password Disclosure
N/A
CWE
Product Name: ADP Forum
Affected Version From: 2.0.3
Affected Version To: 2.0.3
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2006
Sv(ADP) Forum 2.0.3 Remote Password Disclosure Vulnerability
A vulnerability in Sv(ADP) Forum 2.0.3 allows an attacker to remotely disclose the admin password by accessing the admin.txt file. The attacker can also register and inject the info in any cookie editor such as FireFox or Opera.
Mitigation:
Ensure that the admin.txt file is not accessible to unauthorized users.