Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CoffeeCup Software Password Wizard远程密码泄露漏洞
Vulnerability Description
CoffeeCup软件一款自动对页面建立密码保护的程序,建立后如果用户输入验证信息正确就转到指定的页面,否则就会重定向其他警告URL。 CoffeeCup Software Password Wizard 4.0版本不充分保护用户名和密码信息,远程攻击者可以利用这个漏洞通过查看源代码获得敏感验证信息。
CVSS Information
N/A
Vulnerability Type
N/A