6.2 Medium
AI Score
Confidence
Low
0.017 Low
EPSS
Percentile
87.8%
PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt.
secunia.com/advisories/8392
securityreason.com/securityalert/3653
www.securityfocus.com/archive/1/315895/30/25400/threaded
www.securityfocus.com/bid/7167
www.securitytracker.com/id?1006360
exchange.xforce.ibmcloud.com/vulnerabilities/11609