Sensitive Information Disclosure in NetObjects Fusion 9 (NOF9) via Rollbacklog.xml File

Sensitive Information Disclosure in NetObjects Fusion 9 (NOF9) via Rollbacklog.xml File

CVE-2005-3923 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

NetObjects Fusion 9 (NOF9) allows remote attackers to obtain sensitive information, including passwords, by downloading the _versioning_repository_/rollbacklog.xml file, then using it to download and modify the associated ZIP file to edit and republish the site.

Learn more about our Web Application Penetration Testing UK.