Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for path/stats.mdb.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
2Enetworx StatCountex web根目录敏感信息泄露漏洞
Vulnerability Description
StatCountex 是一个完全由asp写成的站点跟踪统计,分析,报告的应用程序,它将从你站点访客搜集来的数据和信息存储到一个Access数据库内。 StatCounteX存在储敏感信息泄露漏洞。StatCounteX在web根目录下存储敏感信息,并且没有进行充分的访问控制限制,远程攻击者可以借助对path/stats.mdb的一个直接请求,下载数据文件。
CVSS Information
N/A
Vulnerability Type
N/A