cve/2004/CVE-2004-2060.md
2024-06-09 00:33:16 +00:00

752 B

CVE-2004-2060

Description

ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.

POC

Reference

Github

No PoCs found on GitHub currently.