Collected research
Unauthenticated Backup and Password Disclosure In HandsomeWeb SOS Webpages cve-2014-3445
CVE-2014-3445
HandsomeWeb SOS Webpages leaves backup.php reachable without authentication, and when the MD5 key parameter is wrong the error message returns the correct key. Replaying that key downloads the site's backup files, which disclose the administrator's password hash.
Record
- Document
- CVE-2014-3445
- Published by
- Portcullis
- Format
- Advisory
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Portcullis, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .