Vulnerabilities > CVE-2007-1192 - Unspecified vulnerability in Hyperbook Guestbook 1.30
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN hyperbook
exploit available
Summary
Thomas R. Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an admin password hash via a direct request for data/gbconfiguration.dat.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | HyperBook Guestbook 1.3 GBConfiguration.DAT Hashed Password Information Disclosure Vulnerability. CVE-2007-1192. Remote exploit for windows platform |
id | EDB-ID:29687 |
last seen | 2016-02-03 |
modified | 2007-02-28 |
published | 2007-02-28 |
reporter | PeTrO |
source | https://www.exploit-db.com/download/29687/ |
title | HyperBook Guestbook 1.3 GBConfiguration.DAT Hashed Password Information Disclosure Vulnerability |
References
- http://downloads.securityfocus.com/vulnerabilities/exploits/22754.py
- http://downloads.securityfocus.com/vulnerabilities/exploits/22754.py
- http://osvdb.org/33868
- http://osvdb.org/33868
- http://secunia.com/advisories/24392
- http://secunia.com/advisories/24392
- http://www.securityfocus.com/bid/22754
- http://www.securityfocus.com/bid/22754