Record summary

CVE-2007-1192 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

Thomas R. Pasawicz HyperBook Guestbook 1.30 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download an admin password hash via a direct request for data/gbconfiguration.dat.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBHyperBook Guestbook 1.3 - GBConfiguration.DAT Hashed Password Information DisclosureExploitDB exploitby PeTrONot analyzed1 file
ExploitDB

PoC details

References

5