Vulnerabilities > CVE-2007-0312 - Information Disclosure vulnerability in Wcsimple Poll

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
NONE
Availability impact
NONE
network
low complexity
wcsimple-poll

Summary

wcSimple Poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password hashes via a direct request for password.txt.

Vulnerable Configurations

Part Description Count
Application
Wcsimple_Poll
1