Insecure Storage of Credentials in Gurgens (GASoft) Ultimate Forum 1.0

Insecure Storage of Credentials in Gurgens (GASoft) Ultimate Forum 1.0

CVE-2005-1648 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Gurgens (GASoft) Ultimate Forum 1.0 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and passwords.

Learn more about our Web App Pen Testing.