Synopsis
Credentials may be exposed by the remote web application.
Description
The remote host is running EZsite Forum.
It is reported that this software stores usernames and passwords in plaintext form in the 'Database/EZsiteForum.mdb' file. A remote user can reportedly download this database.
Solution
No solution was available at the time. Configure your web server to disallow the download of .mdb files.
Plugin Details
File Name: EZsiteForum.nasl
Supported Sensors: Nessus
Vulnerability Information
Excluded KB Items: Settings/disable_cgi_scanning