CVE-2005-1586
N/A
N/A
Summary
Quick.Forum 2.1.6 stores potentially sensitive information such as usernames, banned IP addresses, censored words, and backups under the web document root, which allows remote attackers to obtain that information via a direct request to (1) db/users.txt, (2) db/banList.txt, (3) db/censureWords.txt, or (4) backup files.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html
- http://secunia.com/advisories/15200
- http://www.osvdb.org/16328
- http://www.osvdb.org/16329
References
- http://lostmon.blogspot.com/2005/05/quickforum-topic-field-xss-and-page.html
- http://secunia.com/advisories/15200
- http://www.osvdb.org/16328
- http://www.osvdb.org/16329
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.