Vulnerabilities > CVE-2006-4487 - Information Disclosure vulnerability in Dupoll 3.0/3.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |