ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for xportal.mdb.
                
            References
                    Configurations
                    History
                    No history.
Information
                Published : 2008-12-15 18:00
Updated : 2025-04-09 00:30
NVD link : CVE-2008-5562
Mitre link : CVE-2008-5562
CVE.ORG link : CVE-2008-5562
JSON object : View
Products Affected
                aspapps
- aspportal
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
