OSVDB ID: 33868

Title: HyperBook Guestbook data/gbconfiguration.dat Direct Request Information Disclosure

Info

Disclosure

Feb 28, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

HyperBook Guestbook contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when requesting data/gbconfiguration.dat directly, which will disclose the administrator's MD5 password hash to a remote attacker.

Classification

Location: Remote / Network Access
Impact: Loss of Confidentiality
Solution: Solution Unknown
Exploit: Exploit Public
Disclosure: Third-party Verified, Uncoordinated Disclosure
OSVDB: Web Related

Solution

OSVDB is not currently aware of a solution for this vulnerability.

Products

Thomas R. Pasawicz

HyperBook Guestbook

1.30

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/33868