CVE-2007-6603: Medium severity HotScripts Hot Or Not Clone vulnerability
Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a direct request to control/backup/backup.php, which generates a backup/dump/backup.sql file that can be downloaded via a direct request to control/downloadfile.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6603?
CVE-2007-6603 is considered a critical vulnerability due to the potential exposure of sensitive administrator credentials.
How do I fix CVE-2007-6603?
To fix CVE-2007-6603, implement proper access controls to restrict unauthorized access to backup files and the backup script.
What are the implications of CVE-2007-6603?
The implications of CVE-2007-6603 include unauthorized access to administrator username and password, leading to potential complete compromise of the affected system.
Which software is affected by CVE-2007-6603?
CVE-2007-6603 affects the Hot or Not Clone script developed by Hotscripts.
Can CVE-2007-6603 be exploited remotely?
Yes, CVE-2007-6603 can be exploited remotely by attackers who directly request the vulnerable backup script.