FireAnt 1.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv. Additional information available at:
http://secunia.com/advisories/34359/
Publication date: Tue, 24 Mar 2009 19:30:00 +0000