ATutor 1.5.1, and possibly earlier versions, stores temporary chat logs under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain user chat conversations via direct requests to those files.
References
Link | Resource |
---|---|
http://marc.info/?l=bugtraq&m=112671176100432&w=2 | |
http://rgod.altervista.org/atutor151.html | Exploit Vendor Advisory |
http://securityreason.com/securityalert/9 | |
http://www.securityfocus.com/bid/14832 | Exploit |
http://marc.info/?l=bugtraq&m=112671176100432&w=2 | |
http://rgod.altervista.org/atutor151.html | Exploit Vendor Advisory |
http://securityreason.com/securityalert/9 | |
http://www.securityfocus.com/bid/14832 | Exploit |
Configurations
History
21 Nov 2024, 00:00
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=112671176100432&w=2 - | |
References | () http://rgod.altervista.org/atutor151.html - Exploit, Vendor Advisory | |
References | () http://securityreason.com/securityalert/9 - | |
References | () http://www.securityfocus.com/bid/14832 - Exploit |
Information
Published : 2005-09-16 22:03
Updated : 2024-11-21 00:00
NVD link : CVE-2005-2956
Mitre link : CVE-2005-2956
CVE.ORG link : CVE-2005-2956
JSON object : View
Products Affected
adaptive_technology_resource_centre
- atutor
CWE