eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt.
References
Configurations
History
20 Nov 2024, 23:41
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2002-07/0412.html - Exploit, Patch | |
References | () http://www.iss.net/security_center/static/9733.php - | |
References | () http://www.securityfocus.com/bid/5369 - |
Information
Published : 2002-07-31 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2002-1449
Mitre link : CVE-2002-1449
CVE.ORG link : CVE-2002-1449
JSON object : View
Products Affected
frederic_tyndiuk
- eupload
CWE