Vulnerabilities > CVE-2007-3061 - Credentials Management vulnerability in Cactusoft Cactushop
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
NONE Availability impact
NONE Summary
Cactushop 6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) cactushop6.mdb or (2) cactushop5.mdb.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | CactuShop v6 Database Disclosure Vulnerability. CVE-2007-3061. Webapps exploit for asp platform |
id | EDB-ID:10686 |
last seen | 2016-02-01 |
modified | 2009-12-26 |
published | 2009-12-26 |
reporter | LionTurk |
source | https://www.exploit-db.com/download/10686/ |
title | CactuShop 6.0 - Database Disclosure Vulnerability |