Vulnerabilities > CVE-2007-0532 - Information Disclosure vulnerability in Tuan DO Uploader 6Beta1

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
tuan-do

Summary

Tuan Do Uploader (aka php-uploader) 6 beta 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrator password hash via a direct request for userdata/user_1.txt.

Vulnerable Configurations

Part Description Count
Application
Tuan_Do
1