soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/10690 | vdb entry |
http://www.securityfocus.com/bid/6243 | vdb entry |
http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2002-11/0329.html | mailing list exploit |
http://online.securityfocus.com/archive/1/300992 | mailing list exploit |
http://securityreason.com/securityalert/3243 | third party advisory exploit |