Vulnerabilities > CVE-2006-1412 - Unspecified vulnerability in TFT Gallery TFT Gallery 0.10
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN tft-gallery
exploit available
Summary
TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a direct request to admin/passwd.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | TFT Gallery <= 0.10 [Password Disclosure] Remote Exploit. CVE-2006-1412. Webapps exploit for php platform |
file | exploits/php/webapps/1611.pl |
id | EDB-ID:1611 |
last seen | 2016-01-31 |
modified | 2006-03-25 |
platform | php |
port | |
published | 2006-03-25 |
reporter | undefined1_ |
source | https://www.exploit-db.com/download/1611/ |
title | TFT Gallery <= 0.10 - Password Disclosure Remote Exploit |
type | webapps |
References
- http://secunia.com/advisories/19411
- http://secunia.com/advisories/19411
- http://www.securityfocus.com/archive/1/453471/100/0/threaded
- http://www.securityfocus.com/archive/1/453471/100/0/threaded
- http://www.securityfocus.com/archive/1/453485/100/0/threaded
- http://www.securityfocus.com/archive/1/453485/100/0/threaded
- http://www.securityfocus.com/bid/17250
- http://www.securityfocus.com/bid/17250
- http://www.vupen.com/english/advisories/2006/1115
- http://www.vupen.com/english/advisories/2006/1115
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25465
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25465
- https://www.exploit-db.com/exploits/1611
- https://www.exploit-db.com/exploits/1611