8392Third-party advisory
http://secunia.com/advisories/8392 CVE-2003-1541
Planetmoon - Guestbook Clear Text Password Retrieval
Record summary
CVE-2003-1541 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPlanetmoon - Guestbook Clear Text Password RetrievalExploitDB exploitby subjNot analyzed1 file
References
73653Third-party advisory
http://securityreason.com/securityalert/3653 20030321 Guestbook tr3.amailing list
http://www.securityfocus.com/archive/1/315895/30/25400/threaded 7167vdb entry
http://www.securityfocus.com/bid/7167 1006360vdb entry
http://www.securitytracker.com/id?1006360 guestbooktr3a-plaintext-password-disclosure(11609)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/11609 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-1541