First published: Fri Dec 31 2004(Updated: )
AJ-Fork 167 does not restrict access to directories such as (1) data, (2) inc, (3) plugins, (4) skins, or (5) tools, which allows remote attackers to list files in those directories via a direct HTTP request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aj-fork Aj-fork | =167 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1572 has a moderate severity level due to potential information disclosure resulting from unrestricted directory access.
To address CVE-2004-1572, implement access controls to restrict directory listing and secure sensitive directories.
CVE-2004-1572 affects AJ-Fork version 167.
The consequences of CVE-2004-1572 include unauthorized access to sensitive files and potential leakage of information.
Yes, CVE-2004-1572 can be exploited remotely through direct HTTP requests to the unsecured directories.