Description
Devise is a flexible authentication solution for Rails with Warden.
This page is using a weak Devise password. Invicti was able to guess the credentials required to access this page. A weak password is short, common, a system default, or something that could be rapidly guessed by executing a brute force attack using a subset of all possible passwords, such as words in the dictionary, proper names, words based on the user name or common variations on these themes.
Remediation
Enforce a strong password policy. Don't permit weak passwords or passwords based on dictionary words.
References
Related Vulnerabilities
WordPress Plugin PICA Photo Gallery 'imgname' Parameter Information Disclosure (1.0)
WordPress Plugin Simple History Information Disclosure (1.0.7)
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-5104)
WordPress Plugin User Profile Picture Information Disclosure (2.4.0)