Kshout 2.x and 3.x stores settings.dat under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2005-08-03T04:00:00
Updated: 2024-08-07T22:29:59.350Z
Reserved: 2005-08-03T00:00:00
Link: CVE-2005-2443

No data.

Status : Deferred
Published: 2005-08-03T04:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2005-2443

No data.