Vulnerabilities > CVE-2006-6890 - Information Disclosure vulnerability in Voc-Project Voodoo Chat 1.0Rc1B
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remote attackers to download passwords via a direct request for data/users.dat.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Voodoo chat 1.0RC1b (users.dat) Password Disclosure Vulnerability. CVE-2006-6890. Webapps exploit for php platform |
file | exploits/php/webapps/3044.txt |
id | EDB-ID:3044 |
last seen | 2016-01-31 |
modified | 2006-12-30 |
platform | php |
port | |
published | 2006-12-30 |
reporter | bd0rk |
source | https://www.exploit-db.com/download/3044/ |
title | Voodoo chat 1.0RC1b users.dat Password Disclosure Vulnerability |
type | webapps |