Vulnerabilities > Thenetguys > Aspired2Poll

DATE CVE VULNERABILITY TITLE RISK
2009-03-02 CVE-2008-6354 Permissions, Privileges, and Access Controls vulnerability in Thenetguys Aspired2Poll
The Net Guys ASPired2poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to ASPired2poll.mdb.
network
low complexity
thenetguys CWE-264
5.0