Web Hack List

Collected research

Unauthenticated Backup and Password Disclosure In HandsomeWeb SOS Webpages cve-2014-3445

CVE-2014-3445

HandsomeWeb SOS Webpages leaves backup.php reachable without authentication, and when the MD5 key parameter is wrong the error message returns the correct key. Replaying that key downloads the site's backup files, which disclose the administrator's password hash.

Record

Document
CVE-2014-3445
Published by
Portcullis
Format
Advisory
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Portcullis, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .