PDshopPro stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) /pdshoppro.mdb, (2) /data/pdshoppro.mdb, or (3) /shoppro/data/pdshoppro.mdb.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2006-10-06T21:00:00Z

Updated: 2024-09-17T00:41:53.110Z

Reserved: 2006-10-06T00:00:00Z

Link: CVE-2006-5197

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2006-10-10T04:06:00.000

Modified: 2008-09-05T21:11:39.467

Link: CVE-2006-5197

cve-icon Redhat

No data.