Planetmoon - Guestbook Clear Text Password Retrieval

EDB-ID:

22408


Author:

subj

Type:

webapps


Platform:

CGI

Date:

2003-03-21


source: https://www.securityfocus.com/bid/7167/info

A vulnerability has been reported in Planetmoon Guestbook. It has been reported that remote users may be able to retrieve clear text password lists. Access to this data may allow an attacker to carry out further attacks against a target user.

http://[somehost]/[gb_dir]/files/passwd.txt