CVE-2010-0765: Medium severity fipsASP Fipsforum vulnerability
Published Mar 2, 2010
·Updated
fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/forumFips.mdb.
Affected Software
1 affected component
fipsASP Fipsforum=2.6
Event History
Mar 2, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0765?
CVE-2010-0765 is considered to have a medium severity due to the exposure of sensitive information.
2
How do I fix CVE-2010-0765?
To fix CVE-2010-0765, restrict access to the _database/forumFips.mdb file to prevent unauthorized downloads.
3
What are the potential impacts of CVE-2010-0765?
The potential impacts of CVE-2010-0765 include unauthorized access to sensitive data which can lead to data breaches.
4
Which software is affected by CVE-2010-0765?
CVE-2010-0765 affects the FipsForum version 2.6.
5
Can CVE-2010-0765 be exploited remotely?
Yes, CVE-2010-0765 can be exploited remotely due to insufficient access controls allowing direct requests.