Vulnerabilities > Yasirpro

DATE CVE VULNERABILITY TITLE RISK
2010-04-13 CVE-2009-4766 Permissions, Privileges, and Access Controls vulnerability in Yasirpro Ms-Pro Portal Scripti 1.0/1.2
YP Portal MS-Pro Surumu (aka MS-Pro Portal Scripti) 1.0 and 1.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for galeri/database/db.mdb.
network
low complexity
yasirpro CWE-264
5.0