Vulnerabilities > Ohhasp

DATE CVE VULNERABILITY TITLE RISK
2007-01-09 CVE-2007-0152 Information Disclosure vulnerability in Ohhasp
OhhASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/OhhASP.mdb.
network
low complexity
ohhasp
7.5