UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eventpublisher.txt.
References
Configurations
History
21 Nov 2024, 00:08
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/ref/24/24236-upoint.txt - | |
References | () http://secunia.com/advisories/19727 - | |
References | () http://www.osvdb.org/24237 - | |
References | () http://www.securityfocus.com/bid/17647 - |
Information
Published : 2006-04-15 23:02
Updated : 2025-04-03 01:03
NVD link : CVE-2006-1437
Mitre link : CVE-2006-1437
CVE.ORG link : CVE-2006-1437
JSON object : View
Products Affected
upoint
- at1_event_publisher
CWE