Microsoft Frontpage Stores Form Results In A De vulnerability report
vulnerabilities.aspcode.net
Phase:
Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.
References
BUGTRAQ:Tuesday, August 24, 1999 Front Page form_results | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93582550911564&w=2
Votes:
Proposed (Wednesday, September 12, 2001)
Comments:
ACCEPT(1) Wall | MODIFY(1) Frech | NOOP(2) Foat, Cole
F7:
Frech> XF:frontpage-formresults-world-readable(8362)
Tagged as
/_private/form_resultstxt
world-readable
information
accessible
attackers
FrontPage
Microsoft
sensitive
submitted
possibly
document
location
results
default
remote
stores
allows
users
which
other
root
read
form