ATutor 1.5.1, and possibly earlier versions, stores temporary chat logs under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain user chat conversations via direct requests to those files.
                
            References
                    | Link | Resource | 
|---|---|
| http://marc.info/?l=bugtraq&m=112671176100432&w=2 | |
| http://rgod.altervista.org/atutor151.html | Exploit Vendor Advisory | 
| http://securityreason.com/securityalert/9 | |
| http://www.securityfocus.com/bid/14832 | Exploit | 
Configurations
                    History
                    No history.
Information
                Published : 2005-09-16 22:03
Updated : 2016-10-18 03:31
NVD link : CVE-2005-2956
Mitre link : CVE-2005-2956
CVE.ORG link : CVE-2005-2956
JSON object : View
Products Affected
                adaptive_technology_resource_centre
- atutor
 
CWE
                